Benign Download

Trojan-PSW.Win32.OnLineGames.ajkx

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-256cac5a8226914b9bd7f06dee4302fbe7c560e95145d6887e809397784020cf301
MaleculeMdTh

Evidence

Detects an XORed URL in an executable 0x5c9c–0x5d5c
⋯3 more rows
0x5ccc7475705c44656661754c742e44415400tup\DefauLt.DAT.
0x5cdcd3cfcfcb819494cccccc95d5d2cedfcd................
0x5cecdf95d8d4d694d6d2d5dcd1d2dad594d7................
⋯7 more rows
Encoded content decoded: xor 0x5dd0–0x5eb0
⋯3 more rows
0x5e00578bf0e88bb6a400000085f675e40000W...........u...
0x5e10d3cfcfcb819494cccccc95d5d2cedfcd................
0x5e20df95d8d4d694dcdad5da94d7d2d595da................
0x5e30c8cb00009ec884da869ec89dc8869ec8................
0x5e409dce869ec89dcb869ec89dc8cb869ec8................
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.