Benign Download

Trojan-PSW.Win32.QQPass.bhf

Detects an XORed URL in an executable
SHA-256f071386324aff08e3a71b4fba4284f162c5ddbc6b60769dd2f5c398e67cc49d6
MaleculeTh

Evidence

Detects an XORed URL in an executable 0x5464–0x5524
⋯3 more rows
0x5494eb5f5e5b8be55dc3ffffffff07000000._^[..].........
0x54a4687474703a2f2f00ffffffff01000000http://.........
0x54b42f000000558bec81c4ccfbffff5333c9/...U........S3.
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.