Benign Download

Trojan-PSW.Win32.QQPass.coj

Detects an XORed URL in an executable
SHA-256b2195bf0192ea1806c8850fa5b3ef0fb847eebcca92ddcdda2d436b34d1bdee4
MaleculeTh

Evidence

Detects an XORed URL in an executable 0xa3c7–0xa477
⋯3 more rows
0xa3f70000000000000000003b3f3f3d38382a.........;??=88*
0xa4076478787c3623237b656765213d227a65dxx|6##{ege!="ze
0xa4176f7c22626978235d5d226d7f7c2ab3d9o|"bix#]]"m.|*..
⋯6 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.