Benign Download

Trojan-PSW.Win32.QQPass.bpz

Detects an XORed URL in an executable
SHA-256dc3ecf442045c5c64828751e288381b7cda018bf6e88375c446c7a2172255a60
MaleculeTh

Evidence

Detects an XORed URL in an executable 0x4384–0x4444
⋯3 more rows
0x43b45e5b59595dc30000ffffffff23000000^[YY].......#...
0x43c4687474703a2f2f666c6173682e636869http://flash.chi
0x43d46e6172656e2e636f6d2f69702f69702enaren.com/ip/ip.
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.