Benign Download

Trojan-PSW.Win32.QQPass.bpy

Detects an XORed URL in an executableEncoded content decoded: xor
SHA-256546e72e2cde9b9e386debef88437276fbf248c459de04429c5b55b5b0c4f711b
MaleculeMdTh

Evidence

Detects an XORed URL in an executable 0x4751–0x4811
⋯3 more rows
0x4781f08bc35e5b595dc3ffffffff07000000...^[Y].........
0x4791687474703a2f2f00ffffffff01000000http://.........
0x47a17b000000ffffffff010000007d000000{...........}...
⋯7 more rows
Encoded content decoded: xor 0x83c0–0x8420
⋯3 more rows
0x83f000000000000000000000000000000000................
0x84006478787c3623237d7d22353c3f393a22dxx|6##}}"5<?9:"
0x84106f6361226f622338386b612368603c3foca"ob#88ka#h`<?
0x8420223d39227874782a457a614d "=9"xtx*EzaM

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.