Benign Download

Trojan-GameThief.Win32.Ganhame.g

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-256a336f6c80a52042fda2681ee43057115cf47367481370c309c5737de87bbaa06
MaleculeMdTh

Evidence

Detects an XORed URL in an executable 0x10b58–0x10c28
⋯3 more rows
0x10b885b8be55dc2040000ffffffff07000000[..]............
0x10b98687474703a2f2f00ffffffff08000000http://.........
0x10ba868747470733a2f2f00000000ffffffffhttps://........
0x10bb8020000000d0a0000ffffffff05000000................
⋯7 more rows
Encoded content decoded: xor 0x118d4–0x119b4
⋯3 more rows
0x119048a3e00c04fc9e26effffffff3d000000.>..O..n....=...
0x11914e8f4f4f0baafaff3e5f2f6e9e3e5aeb1................
0x11924b0b0b0f9aee3efedaee3eeafb1b0b0b0................
0x11934f9afb1b0b0b0d9d3e5f2f6e9e3e5afd0................
0x11944e1f3f3d3e5e1f2e3e8aee1f3f0000000................
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.