Hostile 92% Download

Trojan-Spy.Win32.FlyStudio.ws

Named Trojan-Spy, sandbox evasion

Detects executables potentially checking for WinJail sandbox window
SHA-2563017342d44d09933a40661f5587fd310514213b211b465c3962bfd4b07d2cb52
MaleculeTh

Evidence

Detects executables potentially checking for WinJail sandbox window 0x1e02–0x1f82
⋯7 more rows
0x1e720000626f7200626f657200626f6f7200..bor.boer.boor.
0x1e824166783a3430303030303a3000c8b7b6Afx:400000:0....
0x1e92a8000100000004010000010000000001................
⋯15 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.