Benign Download

supq.exe

Detects executables referencing many confidential data stores found in browsers, mail clients, cryptocurreny wallets, etc. Observed in information stealersEncoded content decoded: xor
SHA-256a6208b571ca4e75efb12ab591122540ebcf9dd071be7fcdbbdfe2c787521ff7b
MaleculeMdTh

Evidence

Encoded content decoded: xor 0xdec5–0xdfa5
⋯3 more rows
0xdef5fe00000006173b730100000273de0000......;s....s...
0xdf05067d5a010004027b5a010004027b5801.}Z....{Z....{X.
0xdf1500047d50010004027b5a010004027b59..}P....{Z....{Y
0xdf250100047d51010004027b5a0100047b50...}Q....{Z...{P
0xdf35010004289100000a2d05dd7401000019...(....-..t....
⋯7 more rows
Detects executables referencing many confidential data stores found in browsers, mail clients, cryptocurreny wallets, etc. Observed in information stealers 0x259c85–0x259f35
⋯7 more rows
0x259cf5730077006f007200640073000a000017s.w.o.r.d.s.....
0x259d056c006f00670069006e0073002e006a00l.o.g.i.n.s...j.
0x259d1573006f006e0000192c0022006c006f00s.o.n...,.".l.o.
⋯14 more rows
0x259e0564000019550073006500720073005c00d...U.s.e.r.s.\.
0x259e155000750062006c0069006300000f6b00P.u.b.l.i.c...k.
0x259e256500790033002e0064006200000f6b00e.y.3...d.b...k.
0x259e356500790034002e006400620000116300e.y.4...d.b...c.
0x259e4565007200740039002e00640062000003e.r.t.9...d.b...
⋯15 more rows
Encoded content decoded: xor → base64 0x25ac0c–0x25acdc
⋯3 more rows
0x25ac3c650063007400650064003a0020000037e.c.t.e.d.:. ..7
0x25ac4c5b005000610063006b00650074005200[.P.a.c.k.e.t.R.
0x25ac5c650061006400650072005d0020007500e.a.d.e.r.]. .u.
0x25ac6c6e006500780070006500630074006500n.e.x.p.e.c.t.e.
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.