Benign Download

Backdoor.Win32.Small.gaa

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-256f2affbd7248563927ee8cde6477e2421b3b9a348d4cb9cdfaf8b429fb8419ad2
MaleculeMdTh

Evidence

Encoded content decoded: xor 0xda2c–0xdb0c
⋯3 more rows
0xda5cb7aeeaf0e7000000ffffffff38000000............8...
0xda6ce8f4f4f0baafafe9b1b6b8aef0e8eff4................
0xda7cefe2f5e3ebe5f4aee3efedafe1ece2f5................
0xda8cedf3aff5b1b6b6aff0e1eef4e8e5f2b2................
0xda9cb9aff7b7aeeaf0e700000000558bec6a............U..j
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.