Benign Download

Trojan-PSW.Win32.LdPinch.cu

Detects an XORed URL in an executableEmbedded PE binary at file offset 0x41b3 (~24576 bytes)
SHA-256e3e68d412fb335778af8b7ab7e4b8cfaecafa264f00aef2a7c7bd7e9ffe92dbb
MaleculeMdTh

Evidence

Embedded PE binary at file offset 0x41b3 (~24576 bytes) 0x4173–0x4243
⋯3 more rows
0x41a300000000000000000000000000000000................
0x41b34d5a90000300000004000000ffff0000MZ..............
0x41c3b8000000000000004000000000000000........@.......
0x41d300000000000000000000000000000000................
⋯7 more rows
Detects an XORed URL in an executable 0x105ef2–0x105fb2
⋯3 more rows
0x105f226174696e67735c2e44656661756c745catings\.Default\
0x105f32687474703a2f2f7777772e727361632ehttp://www.rsac.
0x105f426f72672f726174696e67737630312e68org/ratingsv01.h
⋯7 more rows
Percent-encoded content decoded 0x106a04–0x106ae4
⋯3 more rows
0x106a347400556e6b6f776e00556e6b6f776e00t.Unkown.Unkown.
0x106a44474554202f667269656e64736869702fGET /friendship/
0x106a54656d61696c5f7468616e6b5f796f752femail_thank_you/
0x106a643f6661696c65645f75726c3d25324666?failed_url=%2Ff
0x106a747269656e647368697025324673656e64riendship%2Fsend
⋯7 more rows
Query/set system parameters (string) 0x120274–0x120314
0x120274000053686f774f776e6564506f707570..ShowOwnedPopup
0x1202847300000053686f775363726f6c6c4261s...ShowScrollBa
0x1202947200000053686f7757696e646f770000r...ShowWindow..
0x1202a453797374656d506172616d6574657273SystemParameters
0x1202b4496e666f41000000547261636b506f70InfoA...TrackPop
0x1202c475704d656e7500005472616e736c6174upMenu..Translat
⋯5 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.