Benign Download

Trojan-PSW.Win32.QQPass.dfe

Detects an XORed URL in an executable
SHA-2565698a8ea91074f786547337a8a10852265774db0bc18b2895b2b8e5f831e1822
MaleculeTh

Evidence

Detects an XORed URL in an executable 0x83ee–0x849e
⋯3 more rows
0x841e0000000000000000003b3f3e353c392a.........;?>5<9*
0x842e6478787c3623236065796675383b3c22dxx|6##`eyfu8;<"
0x843e7465627b6962393e3c226f6361235d5dteb{ib9><"oca#]]
⋯6 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.