Benign Download

Trojan-Downloader.Win32.Delf.fze

Detects an XORed URL in an executableEmbedded PE binary at file offset 0x26f0 (~122880 bytes)
SHA-256db02943a8665546a5ae9527e884b1f8adef1c848d76894793078e63d9486f5c3
MaleculeTh

Evidence

Embedded PE binary at file offset 0x26f0 (~122880 bytes) 0x26b0–0x2780
⋯3 more rows
0x26e041004700450049004e0046004f000000A.G.E.I.N.F.O...
0x26f04d5a50000200000004000f00ffff0000MZP.............
0x2700b80000000000000040001a0000000000........@.......
0x271000000000000000000000000000000000................
⋯7 more rows
Detects an XORed URL in an executable 0x147fc–0x148bc
⋯3 more rows
0x1482cffffebf85dc38bc0832d8078410001c3....]....-.xA...
0x1483c687474703a2f2f6262732e657166756ehttp://bbs.eqfun
0x1484c2e636f6d2f312e747874000000000000.com/1.txt......
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.