Benign Download

Trojan-PSW.Win32.OnLineGames.apgm

Detects an XORed URL in an executable
SHA-256b535bfa2d9b39edf9241b779d17e7263ef3a7618780a23dd6114dffad8e38b98
MaleculeTh

Evidence

Detects an XORed URL in an executable 0x2930–0x29f0
⋯3 more rows
0x296068e0ffffebe35f5e5b8be55dc2040000h....._^[..]....
0x2970687474703a2f2f00ffffffff01000000http://.........
0x29802f000000ffffffff010000002e000000/...............
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.