Hostile 92% Download

Trojan-Spy.Win32.Pophot.aqs

Named Trojan-Spy, sandbox evasion

Detects executables potentially checking for WinJail sandbox window
SHA-256c19a8a1295c41a8b40f03e2eed20d1431cc6d796ee6848c2ae3d3f7e3bed5de3
MaleculeTh

Evidence

Detects executables potentially checking for WinJail sandbox window 0x4798–0x4918
⋯7 more rows
0x480802000000cac70000ffffffff0c000000................
0x48184166783a3430303030303a3000000000Afx:400000:0....
0x482800000000ffffffff02000000b4cb0000................
⋯15 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.