Benign Download

Trojan-GameThief.Win32.OnLineGames.sine

Detects an XORed URL in an executable
SHA-256c4ba759a54e99251b7fb423e8569db44efb78cfdbe96600d01c8b8b7905edeca
MaleculeTh

Evidence

Detects an XORed URL in an executable 0x2700–0x27c0
⋯3 more rows
0x273070e2ffffebe35f5e5b8be55dc2040000p....._^[..]....
0x2740687474703a2f2f00ffffffff01000000http://.........
0x27502f000000ffffffff010000002e000000/...............
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.