Benign Download

Trojan-PSW.Win32.QQRob.to

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-2560538302d06f9c9fd194841fa45ddec05926350074093257d23ce4b04873a36a3
MaleculeMdTh

Evidence

Detects an XORed URL in an executable 0x4d9d–0x4e5d
⋯3 more rows
0x4dcdf08bc35e5b595dc3ffffffff07000000...^[Y].........
0x4ddd687474703a2f2f00ffffffff01000000http://.........
0x4ded7b000000ffffffff010000007d000000{...........}...
⋯7 more rows
Encoded content decoded: xor 0x7dc0–0x7e20
⋯3 more rows
0x7df000000000000000000000000000000000................
0x7e006478787c3623237d7d223d343d3b393edxx|6##}}"=4=;9>
0x7e103c226f622338386b612368603c3f223d<"ob#88ka#h`<?"=
0x7e2039227874782a437a614d 9"xtx*CzaM

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.