SYMBOLCOMMON_NAMEaka. SYNONYMS
win.fastloader (Back to overview)

FastLoader


FastLoader is a small .NET downloader, which name comes from PDB strings seen in samples. It typically downloads TrickBot. It may create a list of processes and uploads it together with screenshot(s). In more recent versions, it employs simple anti-analysis checks (VM detection) and comes with string obfuscations.

References
2020-01-14MalpediaMalpedia
@online{malpedia:20200114:family:9f9eb7d, author = {Malpedia}, title = {{Family Page for FastLoader}}, date = {2020-01-14}, organization = {Malpedia}, url = {https://malpedia.caad.fkie.fraunhofer.de/details/win.fastloader}, language = {English}, urldate = {2020-01-14} } Family Page for FastLoader
FastLoader

There is no Yara-Signature yet.