Benign Download

Trojan-GameThief.Win32.Nilage.ut

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-256f396773e9210dae1fa6fa87c7de27a3288113e0e969033e0849e6bd0f699a271
MaleculeMdTh

Evidence

Detects an XORed URL in an executable 0x1447c–0x1453c
⋯3 more rows
0x144aceb5f5e5b8be55dc3ffffffff07000000._^[..].........
0x144bc687474703a2f2f00ffffffff01000000http://.........
0x144cc2f000000558bec81c4bcfbffff535657/...U........SVW
⋯7 more rows
Encoded content decoded: xor 0x1773c–0x17a2c
⋯3 more rows
0x1776c6959575300000000ffffffff1e000000iYWS............
0x1777ce8f4f4f0baafaff4f7aee7e1f3e8e3e1................
0x1778cf2e4aee7e1ede1eee9e1aee3efed0000................
0x1779cffffffff1f000000e8f4f4f0baafaff4................
0x177acf7aee7e1f3e8e3e1f2e4aee7e1ede1ee................
0x177bce9e1aee3efedaf00ffffffff28000000............(...
0x177cce8f4f4f0baafaff4f7aee7e1f3e8e3e1................
0x177dcf2e4aee7e1ede1eee9e1aee3efedafe9................
0x177eceee4e5f8aee1f3f000000000ffffffff................
0x177fc2a000000e8f4f4f0f3baafaff4f7aee7*...............
0x1780ce1f3e8aee7e1ede1eee9e1aee3efedaf................
0x1781cc7c1d3c8ccefe7e9eeaee1f3f0f80000................
0x1782cffffffff1b000000e8f4f4f0f3baafaf................
0x1783cf4f7aee7e1f3e8aee7e1ede1eee9e1ae................
0x1784ce3efed00ffffffff1c000000e8f4f4f0................
0x1785cf3baafaff4f7aee7e1f3e8aee7e1ede1................
0x1786ceee9e1aee3efedaf00000000ffffffff................
0x1787c2a000000e8f4f4f0f3baafaff4f7aee7*...............
0x1788cefefe4ecefe3ebaee7e1ede1eee9e1ae................
0x1789ce3efedafe9eee4e5f8aee1f3f0f80000................
0x178acffffffff2a000000e8f4f4f0f3baafaf....*...........
0x178bcf4f7aee7efefe4ecefe3ebaee7e1ede1................
0x178cceee9e1aee3efedafc9eee4e5f8aee1f3................
0x178dcf0f80000ffffffff2b000000e8f4f4f0........+.......
0x178ecbaafaff4f7aee7e1ede1eee9e1aee3ef................
0x178fcedafc7c8cfcdc5afc8efede5dfc3e5ee................
0x1790cf4e5f2aec1d3d000ffffffff16000000................
0x1791ce8f4f4f0baafaff4f7aee7e1ede1eee9................
0x1792ce1aee3efedaf0000ffffffff15000000................
0x1793ce8f4f4f0baafaff4f7aee7e1ede1eee9................
0x1794ce1aee3efed000000ffffffff2e000000................
0x1795ce8f4f4f0baafaff4f7aee7e1ede1eee9................
0x1796ce1aee3efedafe4e5e6e1f5ecf4aee1f3................
0x1797cf0bff5f3e5f2dfecefe3e1f4e5bd0000................
0x1798cffffffff26000000e8f4f4f0f3baafaf....&...........
0x1799cf4f7aee7e1f3e8aee7e1ede1eee9e1ae................
0x179ace3efedafc2ece1eeebaee1f3f0f80000................
0x179bcffffffff28000000e8f4f4f0baafaff4....(...........
0x179ccf7aee7e1f3e8e3e1f2e4aee7e1ede1ee................
0x179dce9e1aee3efedaff3f0e1e3e5aee8f4ed................
0x179ec00000000ffffffff1f000000e8f4f4f0................
0x179fcf3baafaff4f7aee7efefe4ecefe3ebae................
⋯3 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.