Hostile 92% Download

Backdoor.Win32.Poison.kfq

Named backdoor, sandbox evasion

Detects binaries and memory artifacts referencing sandbox product IDs
SHA-256acd4b97eebf0c9b34ee83893ff65fe1f589df157dc94316b89c9b53c8d8277ef
MaleculeTh

Evidence

Detects binaries and memory artifacts referencing sandbox product IDs 0x1f84–0x2164
⋯7 more rows
0x1ff47500630074004900640000002e000000u.c.t.I.d.......
0x2004370036003400380037002d00330033007.6.4.8.7.-.3.3.
0x201437002d003800340032003900390035007.-.8.4.2.9.9.5.
0x202435002d003200320036003100340000005.-.2.2.6.1.4...
0x20342e000000370036003400380037002d00....7.6.4.8.7.-.
0x20443600340034002d0033003100370037006.4.4.-.3.1.7.7.
0x20543000330037002d0032003300350031000.3.7.-.2.3.5.1.
0x2064300000002e00000035003500320037000.......5.5.2.7.
0x207434002d003600340030002d00320036004.-.6.4.0.-.2.6.
⋯15 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.