Trojan.Win32.Dialer.axg
Known Trojan with RAT indicators
Detects Gh0st RAT mentioned in Cylance' Ghost Dragon ReportEmbedded PE binary at file offset 0x2660 (~97739 bytes)
SHA-2561e2ad375a72f6be80a30bf6c204b4c695f8d78020691a1126c08fcbcf4d74263
MaleculeMdTh
Evidence
⋯3 more rows
0x265000000000000000000300420049004e00..........B.I.N.
0x26604d5a90000300000004000000ffff0000MZ..............
0x2670b8000000000000004000000000000000........@.......
0x268000000000000000000000000000000000................
⋯7 more rows
0x15b2a7800b7014c6f6164437572736f724100x...LoadCursorA.
0x15b3a950044657374726f79437572736f7200..DestroyCursor.
0x15b4a0e00426c6f636b496e70757400009902..BlockInput....
0x15b5a53797374656d506172616d6574657273SystemParameters
0x15b6a496e666f41003b0253656e644d657373InfoA.;.SendMess
0x15b7a616765410000d6026b657962645f6576ageA....keybd_ev
⋯5 more rows
⋯7 more rows
0x16c5c53746172740000005479706500000000Start...Type....
0x16c6c52656753657456616c75654578287374RegSetValueEx(st
0x16c7c61727429000000004572726f72436f6eart)....ErrorCon
0x16c8c74726f6c000000004f626a6563744e61trol....ObjectNa
⋯15 more rows
⋯3 more rows
0x16e0c722e64617400000025642e62616b0000r.dat...%d.bak..
0x16e1c0d0a5b253032642f253032642f256420..[%02d/%02d/%d
0x16e2c253032643a253032643a253032645d20%02d:%02d:%02d]
0x16e3c282573290d0a00005d0000000d0a0000(%s)....].......
⋯18 more rows