Benign Download

Trojan-PSW.Win32.QQPass.bhc

Detects an XORed URL in an executable
SHA-256d00a9f9d2ace22e18f110b18b5bca3a4c9a5f62918dde72c86e0164e1f04fa1a
MaleculeTh

Evidence

Detects an XORed URL in an executable 0x61c7–0x6277
⋯3 more rows
0x61f70000000000000000003b3f3f3c39392a.........;??<99*
0x62076478787c36232361696568656d623d3cdxx|6##aiehemb=<
0x62173e226a7e69692266763b226f62235d5d>"j~ii"fv;"ob#]]
⋯6 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.