Benign Download

Worm.Win32.Viking.an

Detects an XORed URL in an executable
SHA-256ced8a2579deb8add754d78ddb1de23bf3ba3caac3b5a11249f64948d5ef43ea4
MaleculeTh

Evidence

Detects an XORed URL in an executable 0x3a14–0x3ad4
⋯3 more rows
0x3a44e5cde5cde5cd0000ffffffff07000000................
0x3a54e8f4f4f0baafaf00ffffffff01000000................
0x3a6420000000558bec81c4b4feffff538bd8 ...U........S..
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.