Benign Download

Trojan-Spy.Win32.Pophot.atq

Detects executables potentially checking for WinJail sandbox window
SHA-256620c033ebc3f6cdcc1fd3f13a4b816db6e0dcb6fc2727c5f31fc117678ef35ab
MaleculeTh

Evidence

Detects executables potentially checking for WinJail sandbox window 0x49bc–0x4b3c
⋯7 more rows
0x4a2c02000000cac70000ffffffff0c000000................
0x4a3c4166783a3430303030303a3000000000Afx:400000:0....
0x4a4c00000000ffffffff02000000b4cb0000................
⋯15 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.