Benign Download

Trojan-PSW.Win32.QQPass.dac

Detects an XORed URL in an executable
SHA-25675bc18b512b12f51f5121c3eff1a1e079a0e5554bdadbc7f710bbb64fed69ccc
MaleculeTh

Evidence

Detects an XORed URL in an executable 0x80cc–0x816c
⋯3 more rows
0x80fc0000000000000000003b3f3e353d3b2a.........;?>5=;*
0x810c6478787c36232375683d227465627b69dxx|6##uh="teb{i
0x811c62393e3c226f6361235d5d3e3c3c3422b9><"oca#]]><<4"
⋯5 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.