Benign Download

Worm.Win32.Socks.by

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-256c18a1c8da0291db216535eae9e36367cc1e2a31380b37d27f0b2febbb02648c9
MaleculeMdTh

Evidence

Detects an XORed URL in an executable 0x5fc–0x6bc
⋯3 more rows
0x62c00000000588240007885400080854000[email protected].@...@.
0x63c6a767672382d2d76637677716a696b2cjvvr8--vcvwqjik,
0x64c6b6c646d2d606d762d00000076697075kldm-`mv-...vipu
⋯7 more rows
Encoded content decoded: xor 0x768–0x848
⋯3 more rows
0x79864730000677372696a69676200000000ds..gsrijigb....
0x7a8515b5156474f5e41777070676c76416dQ[QVGO^AwppglvAm
0x7b86c76706d6e5167765e516770746b6167lvpmnQgv^Qgptkag
0x7c8715e51616a6766776e6700004f6b6761q^Qajgfwng..Okga
0x7d8635667726e0000005d64796467686d64cVgrn...]dydghmd
⋯7 more rows
Encoded content decoded: xor → base64 0x3038–0x3108
⋯3 more rows
0x30686f636573733332466972737400004c00ocess32First..L.
0x3078437265617465546f6f6c68656c703332CreateToolhelp32
0x3088536e617073686f7400006d0147657454Snapshot..m.GetT
0x309869636b436f756e7400007d0045786974ickCount..}.Exit
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.