Benign Download

Trojan-PSW.Win32.Delf.lj

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-256de2dad48ee78dff0d77be2605b6b485c96c2dc12cd5c55bc9da53b8afd60d725
MaleculeMdTh

Evidence

Encoded content decoded: xor 0x5bf4–0x5cd4
⋯3 more rows
0x5c24eb8be55dc3000000ffffffff2d000000...]........-...
0x5c34d3efe6f4f7e1f2e5dccde9e3f2eff3ef................
0x5c44e6f4dcd7e9eee4eff7f3dcc3f5f2f2e5................
0x5c54eef4d6e5f2f3e9efeedcd2f5ee000000................
0x5c64ffffffff02000000f7f90000ffffffff................
⋯7 more rows
Detects an XORed URL in an executable 0x1007c–0x1014c
⋯3 more rows
0x100ac5e5b8be55dc20400ffffffff07000000^[..]...........
0x100bce8f4f4f0baafaf00ffffffff08000000................
0x100cce8f4f4f0f3baafaf00000000ffffffff................
0x100dc020000000d0a0000ffffffff06000000................
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.