Hostile 92% Download

Backdoor.Win32.Kbot.fj

Kbot backdoor with encoded payloads

Detects suspicious single byte XORed keyword 'Mozilla/5.0' - it uses yara's XOR modifier and therefore cannot print the XOR key. You can use the CyberChef recipe linked in the reference field to brute force the used key.Detects an XORed URL in an executable
SHA-256b7cf9a60c2f918b07a4e76eed0736852acfc3a4fb84dbadf654f41f244e97c26
MaleculeMdTh

Evidence

Encoded content decoded: xor 0x508–0x7f8
⋯3 more rows
0x5380000000026f000000000000000000000....&...........
0x548edeeefe8e9eaebe4e5e6e7e0e1e2e3fc................
0x558fdfefff8f9fafbf4f5f6cdcecfc8c9ca................
0x568cbc4c5c6c7c0c1c2c3dcdddedfd8d9da................
⋯3 more rows
0x5a8c3dbdf8ce2f88c99829d978cf9978cde................
0x5b8d985000000000000e1c3d6c5c0c0cd83................
0x5c898829c8c84cfc3c1dccdd8c5cec0c997................
0x5d88ce1ffe5e98c9a829c978cfbc5c2c8c3................
0x5e8dbdf8ce2f88c99829d978cfffa9d978c................
0x5f882e2e9f88cefe0fe8c9d829d82989f9e................
0x6089e85000000000000e1c3d6c5c0c0cd83................
0x61899829c8c84fbc5c2c8c3dbdf978cf997................
⋯13 more rows
0x6f800000000c8cdd8cd00000000d9c8dc00................
0x708fff5fff8e9e1f0efd9dedec9c2d8efc3................
0x718c2d8dec3c0ffc9d8f0ffc9dedac5cfc9................
0x728df000000c1dfd9dcc8cdd8c900000000................
0x738e1c5cfdec3dfc3cad88cdfc9cfd9dec5................
0x748d8d58cd9dcc8cdd8c98cdfc9dedac5cf................
0x758c900000000000000f8c4c5df8cdfc9de................
0x768dac5cfc98cc8c3dbc2c0c3cdc8c5c2cb................
0x7788ccdc2c88cc5c2dfd8cdc0c0c5c2cb8c................
0x788fbc5c2c8c3dbdf8cdfc9cfd9dec5d8d5................
0x7988cd9dcc8cdd8c9df00000000e0c3cfcd................
0x7a8c0ffd5dfd8c9c100fff5fff8e9e1f0ef................
0x7b8d9dedec9c2d8efc3c2d8dec3c0ffc9d8................
0x7c8f0ffc9dedac5cfc9dff0c1dfd9dcc8cd................
0x7d8d8c90000e5c1cdcbc9fccdd8c4000000................
0x7e8e8c5dfdcc0cdd5e2cdc1c900e8c9dfcf................
0x7f8dec5dcd8c5c3c200e3cec6c9cfd8e2cd................
Detects an XORed URL in an executable 0x9c4–0xa84
⋯3 more rows
0x9f4819e999c9c9ced9e9b9aed9b9fd10000................
0xa04c4d8d8dc968383008300000089c88289................
0xa14c88289c88289c80089c88289c88289c8................
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.