Benign Download

Trojan-PSW.Win32.QQPass.bsk

Detects an XORed URL in an executable
SHA-2560e0e9dc8a1944170376f48c9143d19e6ca870eb19fb40af9bbf5d9083d0c40f4
MaleculeTh

Evidence

Detects an XORed URL in an executable 0x439c–0x445c
⋯3 more rows
0x43cc5e5b59595dc30000ffffffff23000000^[YY].......#...
0x43dc687474703a2f2f666c6173682e636869http://flash.chi
0x43ec6e6172656e2e636f6d2f69702f69702enaren.com/ip/ip.
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.