Movatterモバイル変換


[0]ホーム

URL:


  1. Home
  2. Software
  3. FYAnti

FYAnti

FYAnti is a loader that has been used bymenuPass since at least 2020, including to deployQuasarRAT.[1]

ID: S0628
Associated Software: DILLJUICE stage2
Type: MALWARE
Platforms: Windows
Version: 1.0
Created: 22 June 2021
Last Modified: 25 April 2025

Associated Software Descriptions

NameDescription
DILLJUICE stage2

[1]

Enterprise Layer
downloadview

Techniques Used

DomainIDNameUse
EnterpriseT1140Deobfuscate/Decode Files or Information

FYAnti has the ability to decrypt an embedded .NET module.[1]

EnterpriseT1083File and Directory Discovery

FYAnti can search theC:\Windows\Microsoft.NET\ directory for files of a specified size.[1]

EnterpriseT1105Ingress Tool Transfer

FYAnti can download additional payloads to a compromised host.[1]

EnterpriseT1027.002Obfuscated Files or Information:Software Packing

FYAnti has used ConfuserEx to pack its .NET module.[1]

Groups That Use This Software

IDNameReferences
G0045menuPass

[1]

References

×

[8]ページ先頭

©2009-2026 Movatter.jp