Benign Download

Trojan-GameThief.Win32.OnLineGames.wyx

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-256da24def852fb9be66719cc8aefe4a17e1462b7eb26de09f65ec27e24d8d3e5ca
MaleculeMdTh

Evidence

Encoded content decoded: xor 0x2824–0x2904
⋯3 more rows
0x285464656661756c742e6461740001000000default.dat.....
0x2864dcc0c0c48e9b9bd2cd869ac7dbc1dede................
0x2874dede9ad7dbd99bdeded2cd9bd8ddda9a................
0x2884d5c7c4006b65726e656c33322e646c6c....kernel32.dll
0x2894000000004c6f61644c69627261727941....LoadLibraryA
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.