Benign Download

Worm.Win32.Viking.aq

Detects an XORed URL in an executable
SHA-256fa43f7f987984aa94dd998ebd2380c9713391246a0bc1344307d1729e2a517a3
MaleculeTh

Evidence

Detects an XORed URL in an executable 0xd560–0xd620
⋯3 more rows
0xd590646f776e3a000000ffffffff07000000down:...........
0xd5a0e8f4f4f0baafaf00ffffffff03000000................
0xd5b064313a00ffffffff010000002c000000d1:.........,...
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.