Benign Download

Trojan-GameThief.Win32.OnLineGames.udpq

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-256fccdf0f0cbaf3f20c732b209d826e71408ed09d46a7806e78071ea741d9762f5
MaleculeMdTh

Evidence

Encoded content decoded: xor 0x3a22a–0x3a30a
⋯3 more rows
0x3a25a8b0000000000000000000023000000ff...........#....
0x3a26a978b8b8fc5d0d0ccceccc8d1c7c7cfcf................
0x3a27ad1908d98d093869787cdd08f908c8bd1................
0x3a28a9e8c8f00000000000000000000000000................
0x3a29a00000000000000000000000000000000................
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.