Trojan-PSW.Win32.OnLineGames.dz
Detects an XORed URL in an executableEmbedded PE binary at file offset 0xc000 (~86016 bytes)
SHA-256ef16b73e152799a8ddf8cc8cf11d5de05a0fffcc7836b207ec3cf017c2d53b1d
MaleculeTh
Evidence
⋯3 more rows
0xbff000000000000000000000000000000000................
0xc0004d5a50000200000004000f00ffff0000MZP.............
0xc010b80000000000000040001a0000000000........@.......
0xc02000000000000000000000000000000000................
⋯7 more rows
⋯3 more rows
0x10994c3e966dcffffebeb5f5e5b59595dc300..f....._^[YY]..
0x109a4687474703a2f2f00ffffffff01000000http://.........
0x109b42f000000558bec81c44cfaffff535657/...U....L...SVW
⋯7 more rows