Benign Download

Trojan-PSW.Win32.Delf.aed

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-256f66f1ad2ada66132ed3791e9f2d33fa0e20c93b1175798da19e5e61bc47c2df8
MaleculeMdTh

Evidence

Detects an XORed URL in an executable 0x3444–0x3504
⋯3 more rows
0x3474c3e986dcffffebeb5f5e5b59595dc300........_^[YY]..
0x3484687474703a2f2f00ffffffff01000000http://.........
0x34942f000000558bec81c454faffff535633/...U....T...SV3
⋯7 more rows
Encoded content decoded: xor 0x8e8e–0x8f6e
⋯3 more rows
0x8ebefb980b5955597d4c5e5e5d425f59108d...YUY}L^^]B_Y..
0x8ece400072727b64687a7e796c7968100b59@.rr{dhz~ylyh..Y
0x8ede55597d4c5e5e5d425f590b5955597d4cUY}L^^]B_Y.YUY}L
0x8eee5e5e5d425f596c4a4c44438d40007272^^][email protected]
0x8efe687b686379796c7f6a6879108bc00b59h{hcyyl.jhy....Y
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.