Benign Download

Trojan-PSW.Win32.QQPass.pb

Detects an XORed URL in an executable
SHA-25663775fc78e8c233b9b85b25fa785d97ed05ecc7cbb931a12142c3c6a46d6c634
MaleculeTh

Evidence

Detects an XORed URL in an executable 0x49cc–0x4a8c
⋯3 more rows
0x49fceb5f5e5b8be55dc3ffffffff07000000._^[..].........
0x4a0c687474703a2f2f00ffffffff01000000http://.........
0x4a1c2f000000558bec81c4c8fbffff535633/...U........SV3
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.