Benign Download

Hoax.Win32.Agent.di

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-256fbd8a5bab7fe7533c4eb602432117f2dad23c1946cc1fab9aa19691faf235fce
MaleculeMdTh

Evidence

Encoded content decoded: xor 0x191f–0x1a2f
⋯3 more rows
0x194f657457696e646f77546578744100003fetWindowTextA..?
0x195f025472616e736c617465416363656c65.TranslateAccele
0x196f7261746f72410042025472616e736c61ratorA.B.Transla
0x197f74654d65737361676500007573657233teMessage..user3
0x198f322e646c6c00001900436c656172436f2.dll....ClearCo
0x199f6d6d4572726f7200001a00436c6f7365mmError....Close
0x19af48616e646c65002500436f707946696cHandle.%.CopyFil
0x19bf65457841002600436f707946696c6545eExA.&.CopyFileE
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.