Hostile 92% Download

Trojan-GameThief.Win32.WOW.css

Gh0st RAT detection

Detects Gh0st RAT mentioned in Cylance' Ghost Dragon ReportEmbedded PE binary at file offset 0x2070 (~78736 bytes)
SHA-256022eb72830ac3f37eaed4fc7193666854f28eedbaaae990f5f9ee2a51308b289
MaleculeTh

Evidence

Embedded PE binary at file offset 0x2070 (~78736 bytes) 0x2030–0x2100
⋯3 more rows
0x206045000000000000000000000000000000E...............
0x20704d5a90000300000004000000ffff0000MZ..............
0x2080b8000000000000004000000000000000........@.......
0x209000000000000000000000000000000000................
⋯7 more rows
Detects Gh0st RAT mentioned in Cylance' Ghost Dragon Report 0x26a0–0x2830
⋯7 more rows
0x2710d8410010000000002e50414400000000.A.......PAD....
0x272052656753657456616c75654578287374RegSetValueEx(st
0x273061727429000000005479706500000000art)....Type....
0x274053595354454d5c43757272656e74436fSYSTEM\CurrentCo
⋯15 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.