Benign Download

P2P-Worm.Win32.SpyBot.go

Suspiciously packed executable
SHA-256a8f724d4ae83b6dee4f3dbc39625702eba0e9305b1c806f798e8bcb58649bfdb
MaleculeTh

Evidence

Suspiciously packed executable 0x16a81–0x16cf1
⋯7 more rows
0x16af1657456616c7565457841000000001800etValueExA......
0x16b015f5f4765744d61696e41726773008301__GetMainArgs...
0x16b115f736e7072696e746600fe0161746f69_snprintf...atoi
⋯12 more rows
0x16be173747273747200000000820273747274strstr......strt
0x16bf16f6b000000005753325f33322e444c4cok....WS2_32.DLL
0x16c0100000060410000604100006041000060...`A..`A..`A..`
⋯15 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.