Hostile 92% Download

Backdoor.Win32.Poison.ldc

Known backdoor signature

detect PoisonIvy in memory
SHA-2569a246e698694816a9552c58e4fbf66fdd5ed036bfcf82f3446f44b4029e452e4
MaleculeTh

Evidence

detect PoisonIvy in memory 0x1a1–0x321
⋯7 more rows
0x2118acd8aea8ad6b60866d1eb66d1d87309........f..f..s.
0x221663520836681f3b8edfece75eb33c833f5 .f......u.3.3
0x231d34f75d5f7d2f7d18bc2c1c010668bc1.Ou..........f..
⋯15 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.