Benign Download

Trojan-PSW.Win32.QQPass.xl

Detects an XORed URL in an executable
SHA-256581154dd81277b7d6c44520009281c9245b7fe15102b8233548357d90d1c8a1c
MaleculeTh

Evidence

Detects an XORed URL in an executable 0xacf8–0xad88
⋯3 more rows
0xad289006e9105869cc470d3b3f3e343a342a....Xi.G.;?>4:4*
0xad386478787c36232367227864696f226f62dxx|6##g"xdio"ob
0xad48237465696165626b23347d3d3f237d7d#teiaebk#4}=?#}}
⋯4 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.