Benign Download

Trojan-GameThief.Win32.Magania.re

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-256a6f3f371a9697e9087372c3f9a2880168616bcf3785ad8a5816a2eeb83dd30e7
MaleculeMdTh

Evidence

Detects an XORed URL in an executable 0x5d1c–0x5ddc
⋯3 more rows
0x5d4ceb5f5e5b8be55dc3ffffffff07000000._^[..].........
0x5d5c687474703a2f2f00ffffffff01000000http://.........
0x5d6c2f000000558bec51b9890000006a006a/...U..Q.....j.j
⋯7 more rows
Encoded content decoded: xor 0x16444–0x16734
⋯3 more rows
0x164746959575300000000ffffffff1e000000iYWS............
0x16484e8f4f4f0baafaff4f7aee7e1f3e8e3e1................
0x16494f2e4aee7e1ede1eee9e1aee3efed0000................
0x164a4ffffffff1f000000e8f4f4f0baafaff4................
0x164b4f7aee7e1f3e8e3e1f2e4aee7e1ede1ee................
0x164c4e9e1aee3efedaf00ffffffff28000000............(...
0x164d4e8f4f4f0baafaff4f7aee7e1f3e8e3e1................
0x164e4f2e4aee7e1ede1eee9e1aee3efedafe9................
0x164f4eee4e5f8aee1f3f000000000ffffffff................
0x165042a000000e8f4f4f0f3baafaff4f7aee7*...............
0x16514e1f3e8aee7e1ede1eee9e1aee3efedaf................
0x16524c7c1d3c8ccefe7e9eeaee1f3f0f80000................
0x16534ffffffff1b000000e8f4f4f0f3baafaf................
0x16544f4f7aee7e1f3e8aee7e1ede1eee9e1ae................
0x16554e3efed00ffffffff1c000000e8f4f4f0................
0x16564f3baafaff4f7aee7e1f3e8aee7e1ede1................
0x16574eee9e1aee3efedaf00000000ffffffff................
0x165842a000000e8f4f4f0f3baafaff4f7aee7*...............
0x16594efefe4ecefe3ebaee7e1ede1eee9e1ae................
0x165a4e3efedafe9eee4e5f8aee1f3f0f80000................
0x165b4ffffffff2a000000e8f4f4f0f3baafaf....*...........
0x165c4f4f7aee7efefe4ecefe3ebaee7e1ede1................
0x165d4eee9e1aee3efedafc9eee4e5f8aee1f3................
0x165e4f0f80000ffffffff2b000000e8f4f4f0........+.......
0x165f4baafaff4f7aee7e1ede1eee9e1aee3ef................
0x16604edafc7c8cfcdc5afc8efede5dfc3e5ee................
0x16614f4e5f2aec1d3d000ffffffff16000000................
0x16624e8f4f4f0baafaff4f7aee7e1ede1eee9................
0x16634e1aee3efedaf0000ffffffff15000000................
0x16644e8f4f4f0baafaff4f7aee7e1ede1eee9................
0x16654e1aee3efed000000ffffffff2e000000................
0x16664e8f4f4f0baafaff4f7aee7e1ede1eee9................
0x16674e1aee3efedafe4e5e6e1f5ecf4aee1f3................
0x16684f0bff5f3e5f2dfecefe3e1f4e5bd0000................
0x16694ffffffff26000000e8f4f4f0f3baafaf....&...........
0x166a4f4f7aee7e1f3e8aee7e1ede1eee9e1ae................
0x166b4e3efedafc2ece1eeebaee1f3f0f80000................
0x166c4ffffffff28000000e8f4f4f0baafaff4....(...........
0x166d4f7aee7e1f3e8e3e1f2e4aee7e1ede1ee................
0x166e4e9e1aee3efedaff3f0e1e3e5aee8f4ed................
0x166f400000000ffffffff1f000000e8f4f4f0................
0x16704f3baafaff4f7aee7efefe4ecefe3ebae................
⋯3 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.