Benign Download

Trojan-Downloader.Win32.Agent.mlp

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-256ce2ebdf4193e39bb000203b08cccc44a524e5fb2ec1d75ef18592790b7e7f9de
MaleculeMdTh

Evidence

Detects an XORed URL in an executable 0x41ee–0x42ae
⋯3 more rows
0x421ef08bc35e5b595dc3ffffffff07000000...^[Y].........
0x422e687474703a2f2f00ffffffff01000000http://.........
0x423e7b000000ffffffff010000007d000000{...........}...
⋯7 more rows
Encoded content decoded: xor 0x71c0–0x7220
⋯3 more rows
0x71f000000000000000000000000000000000................
0x72006478787c3623237d7d22353c3f393a22dxx|6##}}"5<?9:"
0x72106f6361226f622338386b612368603c3foca"ob#88ka#h`<?
0x7220223d39227874782a457a614d "=9"xtx*EzaM

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.