Benign Download

Trojan-GameThief.Win32.OnLineGames.wzp

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-256c467ced49cda93eb4210d58c43379ec544097eb49ea5d632d8b8b19f2ea62ce9
MaleculeMdTh

Evidence

Encoded content decoded: xor 0x11cc–0x132c
⋯3 more rows
0x11fc00000000000000000000000001b10000................
0x120cd9c5c5c18b9e9ec2dc8282898988889f................
0x121cd2df9ec0d8dbd89ededfd49ec1dec2c5................
0x122c9fd0c2c1000000000000000000000000................
0x123c00000000000000000000000000000000................
⋯3 more rows
0x127c00000000000000000000000000000000................
0x128cd9c5c5c18b9e9ec2dc8282898988889f................
0x129cd2df9ec0d8dbd89ec5c6de9ec1dec2c5................
0x12ac9fd0c2c1000000000000000000000000................
0x12bc00000000000000000000000000000000................
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.