Benign Download

Trojan-GameThief.Win32.OnLineGames.abz

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-256e8a7bc9309ae2f8ebf7f5c1a037645e754d507637f11188ba34f8f05114c0ac4
MaleculeMdTh

Evidence

Detects an XORed URL in an executable 0x2b08–0x2bc8
⋯3 more rows
0x2b3844e4ffffebe35f5e5b8be55dc2040000D....._^[..]....
0x2b48687474703a2f2f00ffffffff01000000http://.........
0x2b582f000000ffffffff010000002e000000/...............
⋯7 more rows
Encoded content decoded: xor 0x4ea2–0x5042
⋯3 more rows
0x4ed2fb980b5955597d4c5e5e5d425f59108d...YUY}L^^]B_Y..
0x4ee2400072727b64687a7e796c7968100b59@.rr{dhz~ylyh..Y
0x4ef255597d4c5e5e5d425f590b5955597d4cUY}L^^]B_Y.YUY}L
0x4f025e5e5d425f596c4a4c44438d40007272^^][email protected]
0x4f12687b686379796c7f6a6879108bc00b59h{hcyyl.jhy....Y
⋯6 more rows
0x4f824e425843596e42434b444a8d40004a42[email protected]
0x4f9203424348594243485a034e4240904a42[email protected]
0x4fa203585d585d4942034e424002444e4243.X]X][email protected]
0x4fb2025503475d4a1a191a194559595d1702.U.G]J....EYY]..
0x4fc2029056008bc000508bc076008bc00070..V....P..v....p
0x4fd28bc051008bc000518bc05b03475d4a8d..Q....Q..[.G]J.
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.