Benign Download

Trojan-PSW.Win32.QQPass.cei

Detects an XORed URL in an executable
SHA-25690b1f8d66078888aa1ef774607bab50cbd19b8fe3b490e601750be16cde2c764
MaleculeTh

Evidence

Detects an XORed URL in an executable 0x3fa0–0x4060
⋯3 more rows
0x3fd05e5b59595dc30000ffffffff23000000^[YY].......#...
0x3fe0687474703a2f2f666c6173682e636869http://flash.chi
0x3ff06e6172656e2e636f6d2f69702f69702enaren.com/ip/ip.
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.