Benign Download

Trojan-PSW.Win32.Agent.jj

Detects an XORed URL in an executable
SHA-256ec6126dc7ec2070b74122710956607bf8c9929d3ff8ad6dca2925276ab2cca09
MaleculeTh

Evidence

Detects an XORed URL in an executable 0x7214–0x72d4
⋯3 more rows
0x72447365727665722e696e6900002f000000server.ini../...
0x7254687474703a2f2f00436f6e74656e742dhttp://.Content-
0x7264547970653a206170706c69636174696fType: applicatio
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.