Benign Download

Trojan-GameThief.Win32.OnLineGames.ltk

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-256fb427ecc817ad44dd7dc572039539b2ce3af565d7cfbf371274a278aaf44a5ef
MaleculeMdTh

Evidence

Detects an XORed URL in an executable 0x5f3c–0x5ffc
⋯3 more rows
0x5f6c000000008b50048b400856894c240400[email protected]$..
0x5f7cfde1e1e5afbabae2e2e2bbfbfce0f1e3................
0x5f8cf1bbf6faf8baf8fcfbf2fffcf4fbbaf9................
⋯7 more rows
Encoded content decoded: xor 0x603c–0x611c
⋯3 more rows
0x606c000000008d84248000000083c40c0000......$.........
0x607cfde1e1e5afbabae2e2e2bbfbfce0f1e3................
0x608cf1bbf6faf8baf2f4fbf4baf9fcfbbbf4................
0x609ce6e50000b0e6aaf4a8b0e6b3e6a8b0e6................
0x60acb3e0a8b0e6b3e5a8b0e6b3e6e5a8b0e6................
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.