Suspicious 80% Download

Trojan-GameThief.Win32.Nilage.yf

Trojan with embedded PE payload

Detects an XORed URL in an executableEmbedded PE binary at file offset 0x7bac (~127572 bytes)
SHA-256ac8821fce99abda1534dff0ae6c6396fdd1399c1af000bb33a634454b375f37b
MaleculeMdTh

Evidence

Detects an XORed URL in an executable 0x4224–0x42e4
⋯3 more rows
0x425468ec4840006a006a00e8c2ebffff5ac3[email protected].
0x4264687474703a2f2f7777772e6162632e63http://www.abc.c
0x42746f6d2f686568652f3132332e65786500om/hehe/123.exe.
⋯7 more rows
Encoded content decoded: base64 0x6073–0x6193
⋯3 more rows
0x60a30067000000ffffffffa0020000b0b0a0.g..............
0x60b3e8f4f4f0baafaff7f7f7aef1f5e3e8e5................
0x60c3eee7f3e8e9aee3efedaff3e8eff7b2af................
0x60d3f3e5eee4ede1e9ecaee1f3f0bff4efed................
0x60e3e1e9ecbdeeedc0eeedaee3efeda6ede1................
0x60f3e9ece2efe4f9bd0042c669bf5b424242........B.i.[BBB
0x610342424242424242424242424242424242BBBBBBBBBBBBBBBB
0x611342424242424242424242424242424242BBBBBBBBBBBBBBBB
0x612342424242424242424242424242424242BBBBBBBBBBBBBBBB
⋯7 more rows
Embedded PE binary at file offset 0x7bac (~127572 bytes) 0x7b6c–0x7c3c
⋯3 more rows
0x7b9c410049004e00490043004f004e007d31A.I.N.I.C.O.N.}1
0x7bac4d5a50000200000004000f00ffff0000MZP.............
0x7bbcb80000000000000040001a0000000000........@.......
0x7bcc00000000000000000000000000000000................
⋯7 more rows
Encoded content decoded: xor 0x214d4–0x217b4
⋯3 more rows
0x21504e9e1aee3efedaf00ffffffff28000000............(...
0x21514e8f4f4f0baafaff4f7aee7e1f3e8e3e1................
0x21524f2e4aee7e1ede1eee9e1aee3efedafe9................
0x21534eee4e5f8aee1f3f000000000ffffffff................
0x215442a000000e8f4f4f0f3baafaff4f7aee7*...............
0x21554e1f3e8aee7e1ede1eee9e1aee3efedaf................
0x21564c7c1d3c8ccefe7e9eeaee1f3f0f80000................
0x21574ffffffff1b000000e8f4f4f0f3baafaf................
0x21584f4f7aee7e1f3e8aee7e1ede1eee9e1ae................
0x21594e3efed00ffffffff1c000000e8f4f4f0................
0x215a4f3baafaff4f7aee7e1f3e8aee7e1ede1................
0x215b4eee9e1aee3efedaf00000000ffffffff................
0x215c42a000000e8f4f4f0f3baafaff4f7aee7*...............
0x215d4efefe4ecefe3ebaee7e1ede1eee9e1ae................
0x215e4e3efedafe9eee4e5f8aee1f3f0f80000................
0x215f4ffffffff2a000000e8f4f4f0f3baafaf....*...........
0x21604f4f7aee7efefe4ecefe3ebaee7e1ede1................
0x21614eee9e1aee3efedafc9eee4e5f8aee1f3................
0x21624f0f80000ffffffff2b000000e8f4f4f0........+.......
0x21634baafaff4f7aee7e1ede1eee9e1aee3ef................
0x21644edafc7c8cfcdc5afc8efede5dfc3e5ee................
0x21654f4e5f2aec1d3d000ffffffff16000000................
0x21664e8f4f4f0baafaff4f7aee7e1ede1eee9................
0x21674e1aee3efedaf0000ffffffff15000000................
0x21684e8f4f4f0baafaff4f7aee7e1ede1eee9................
0x21694e1aee3efed000000ffffffff2e000000................
0x216a4e8f4f4f0baafaff4f7aee7e1ede1eee9................
0x216b4e1aee3efedafe4e5e6e1f5ecf4aee1f3................
0x216c4f0bff5f3e5f2dfecefe3e1f4e5bd0000................
0x216d4ffffffff26000000e8f4f4f0f3baafaf....&...........
0x216e4f4f7aee7e1f3e8aee7e1ede1eee9e1ae................
0x216f4e3efedafc2ece1eeebaee1f3f0f80000................
0x21704ffffffff28000000e8f4f4f0baafaff4....(...........
0x21714f7aee7e1f3e8e3e1f2e4aee7e1ede1ee................
0x21724e9e1aee3efedaff3f0e1e3e5aee8f4ed................
0x2173400000000ffffffff1f000000e8f4f4f0................
0x21744f3baafaff4f7aee7efefe4ecefe3ebae................
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.