Benign Download

Trojan-GameThief.Win32.Nilage.dhg

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-256f33deaaa7cd0f9426bb9b7684bb65cbac10b7e3caa3a24cf7ab936d97babc12f
MaleculeMdTh

Evidence

Encoded content decoded: xor 0x4080–0x4160
⋯3 more rows
0x40b0f4e5aee5f8e50000ffffffff28000000............(...
0x40c0e8f4f4f0baafaff7f7f7aee7e9f6e5f3................
0x40d0e8e5ececaeeff2e7afe8eff5afe7e5ee................
0x40e0f8e9eee7aee5f8e500000000558bec33............U..3
0x40f0c95151515153565733c05568084e4000.QQQQSVW3.Uh.N@.
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.