Benign Download

Trojan-GameThief.Win32.OnLineGames.yar

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-256aea8a14fe27432640b25bdb01830912b47fe7b5417462b21bffd1999ef44d129
MaleculeMdTh

Evidence

Encoded content decoded: xor 0x3f44–0x4194
⋯3 more rows
0x3f746a016897ffffff518d8e9c0400000000j.h....Q........
0x3f84dcc0c0c48e9b9bd2cd869ac7dbc1dede................
0x3f94dede9ad7dbd99bdeded2cd9bd8ddda9a................
0x3fa4d5c7c4004c6f61644c69627261727945....LoadLibraryE
0x3fb478570000c8a1cffb0000000042000000xW..........B...
⋯9 more rows
0x405400000000000000000000000000000000................
0x40640000000001960000fee2e2e6acb9b9e1................
0x4074e1e1b8ffa3a7a1a5b8f5f8b9faf9f8f1................
0x4084f1f3b9fafff8b8f7e5e6000000000000................
0x409400000000000000000000000000000000................
⋯3 more rows
0x40d400000000000000000000000000000000................
0x40e40000000000000000fee2e2e6acb9b9e1................
0x40f4e1e1b8ffa3a7a1a5b8f5f8b9faf9f8f1................
0x4104f1f3a7b9fafff8b8f7e5e60000000000................
0x411400000000000000000000000000000000................
0x412400000000000000000000000000000000................
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.