Hostile 92% Download

Trojan-Downloader.Win32.QQHelper.bmb

Named Trojan-Downloader, sandbox evasion

Detects executables potentially checking for WinJail sandbox window
SHA-256cff75f057c3734c1d70e3399c2574222ece2b876f464dce9f11930f9ea44a30b
MaleculeTh

Evidence

Detects executables potentially checking for WinJail sandbox window 0xd118–0xd298
⋯7 more rows
0xd188e87357ffff5f5e5b595dc20400000000.sW.._^[Y]......
0xd1984166783a3430303030303a3000000000Afx:400000:0....
0xd1a8427574746f6e00004156502e416c6572Button..AVP.Aler
⋯15 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.