Benign Download

Trojan-Downloader.Win32.Nurech.r

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-256c92e47313145b8d86832fc0f17b764de4708f2ca3d6864b0a51b3334f240355f
MaleculeMdTh

Evidence

Encoded content decoded: xor 0x1dc0–0x1f30
⋯3 more rows
0x1df000000000000000000000000000000000................
0x1e00302c2c286277772e313331752b392c300,,(bww.131u+9,0
0x1e103d2a763b373577697769763d203d5800=*v;75wiwiv= =X.
0x1e2000000000000000000000000000000000................
0x1e3000000000000000000000000000000000................
0x1e400000000000000000000000302c2c2862...........0,,(b
0x1e5077772e313331752b392c303d2a763b37ww.131u+9,0=*v;7
0x1e6035776977222d28393b3039763d203d585wiw"-(9;09v= =X
0x1e7000000000000000000000000000000000................
0x1e8000000000000000000000000000000000................
0x1e90000000000000302c2c286277772e3133......0,,(bww.13
0x1ea031752b392c303d2a763b37357769773b1u+9,0=*v;75wiw;
0x1eb0303131763d203d580000000000000000011v= =X........
0x1ec000000000000000000000000000000000................
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.