Suspicious 80% Download

Trojan-Dropper.Win32.Agent.mg

Signed trojan dropper

Binary contains a UPX packing markerAuthenticode chain CN: EDIPOLE
SHA-256f45181c3ee561a03175158d87c487d05b3c6581dc95294af6591fb4ba8fd537a

Evidence

Compact high-entropy RWX UPX1 section 0x3c0–0x4a0
⋯3 more rows
0x3f05cd505000f25020000c0050026070061\....%......&..a
0x400ffffbffc83ec48b9100033c053555657......H...3.SUVW
0x410be309040008d7c2414f3a58b6c245ced.0.@..|$....l$\.
0x420feffff83c9ffa48bfd33f6f2aef7d149.........3.....I
0x430d1e151e80700095c8bd8253033feff3b..Q....\..%03..;
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.