Benign Download

Trojan.Win32.LowZones.cu

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-256ba7448f44a8397ae8f6541aa53d68c708053f7402ea4d73fd33ddd577b3373c4
MaleculeMdTh

Evidence

Detects an XORed URL in an executable 0x30f0–0x31b0
⋯3 more rows
0x3120314130300000000031413034000000001A00....1A04....
0x3130687474703a2f2f6d6963726f736f6674http://microsoft
0x31402e636f6d000000006261740040656368.com....bat.@ech
⋯7 more rows
Encoded content decoded: xor 0x6fd3–0x7043
⋯3 more rows
0x70030099c0a6949f8e8cd49f829f30000000............0...
0x7013928e8e8ac0d5d58d93889fd495949693................
0x7023949fd79795889fd4999597d5949f8dd5................
0x70338f899f88c8c3d593949e9f82d48a928a................
0x7043fa48000000 .H...

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.