Benign Download

Trojan-PSW.Win32.QQPass.afe

Detects an XORed URL in an executable
SHA-256af38aed3797b56a869c922ed9569b6cd3dae2916c96e9ff5aa8d5809e33292f8
MaleculeTh

Evidence

Detects an XORed URL in an executable 0xd400–0xd490
⋯3 more rows
0xd4306341646472657373003b3f3e35383c2acAddress.;?>58<*
0xd4406478787c362323616d756d3e353d226fdxx|6##amum>5="o
0xd4506223756d23756d7d226d7f7c2a262626b#um#um}"m.|*&&&
⋯4 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.