Benign Download

Trojan-GameThief.Win32.OnLineGames.oof

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-256aa66e71f875684e592e3fe2cfdeb76a2458222c84a0631abb2f34beb4cddc6f2
MaleculeMdTh

Evidence

Detects an XORed URL in an executable 0x3080–0x3140
⋯3 more rows
0x30b018d9ffffebe35f5e5b8be55dc2040000......_^[..]....
0x30c0687474703a2f2f00ffffffff01000000http://.........
0x30d02f000000ffffffff010000002e000000/...............
⋯7 more rows
Encoded content decoded: xor 0x98da–0x99ba
⋯3 more rows
0x990a4a484b43024f5619191a1a024f43418dJHKC.OV.....OCA.
0x991a40004b43024f5e5514024f4341034541@.KC.O^U..OCA.EA
0x992a4d4b495f035402465c4b1b181b184458MKI_.T.F\K....DX
0x993a585c1603039057018bc001518bc07701X\....W....Q..w.
0x994a8bc001718bc050018bc001508bc00f73...q..P....P...s
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.