Benign Download

Trojan-GameThief.Win32.Nilage.akq

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-256f1713442e9289a80db5fc8e1d836f97e58eaf7dd8beec7ebbfd72fe68b973dc8
MaleculeMdTh

Evidence

Detects an XORed URL in an executable 0x50d8–0x5198
⋯3 more rows
0x5108eb5f5e5b8be55dc3ffffffff07000000._^[..].........
0x5118687474703a2f2f00ffffffff01000000http://.........
0x51282f000000558bec81c4b8fbffff535657/...U........SVW
⋯7 more rows
Encoded content decoded: xor 0xfb50–0xfc30
⋯3 more rows
0xfb80204f4b2100000000ffffffff26000000 OK!........&...
0xfb90e8f4f4f0baafaff7f7f7aee5f9f4f7ae................
0xfba0e3efedaff8f8f8f8aff4b1aff5f0e6e9................
0xfbb0ece5aee1f3f00000558becb934000000........U...4...
0xfbc06a006a004975f953568945fc8b45fce8j.j.Iu.SV.E..E..
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.