Benign Download

Trojan-GameThief.Win32.OnLineGames.amny

Detects an XORed URL in an executable
SHA-256dab63e7f6519d5448653de828860e690adf752bcf236b033560fbee75d9b3f8a
MaleculeTh

Evidence

Detects an XORed URL in an executable 0x2a14–0x2ad4
⋯3 more rows
0x2a4484dfffffebe35f5e5b8be55dc2040000......_^[..]....
0x2a54687474703a2f2f00ffffffff01000000http://.........
0x2a642f000000ffffffff010000002e000000/...............
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.