Benign Download

Trojan-PSW.Win32.QQPass.dax

Detects an XORed URL in an executable
SHA-2568d107e0b7ea514effef706802e8bb0de2f4f84d80fd63f10bca49765dd182be1
MaleculeTh

Evidence

Detects an XORed URL in an executable 0xa1e2–0xa2a2
⋯3 more rows
0xa212bc0a119c9a29edb8729f5d226d7f7c2a.....)..r.]"m.|*
0xa2226478787c3623237b7b7b226e6d656879dxx|6##{{{"nmehy
0xa232226f6361236b63636b6069226974692a"oca#kcck`i"iti*
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.