Hostile 92% Download

Trojan-Spy.Win32.FlyStudio.adr

Sandbox evasion, spyware signature

Detects executables potentially checking for WinJail sandbox window
SHA-2564a47745aaee9f4938fee6941ea653b9508d7d1b5d0f560fab90263fa46b2c4f9
MaleculeTh

Evidence

Detects executables potentially checking for WinJail sandbox window 0x28d0–0x2a50
⋯7 more rows
0x2940636174696f6e0076687474703a2f2f00cation.vhttp://.
0x29504166783a3430303030303a3000c8b7b6Afx:400000:0....
0x2960a8002e657865202d3100626572313233...exe -1.ber123
⋯15 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.