Trojan-GameThief.Win32.OnLineGames.bkvu
GameThief trojan with embedded PE
Detects Gh0st RAT mentioned in Cylance' Ghost Dragon ReportEmbedded PE binary at file offset 0xa070 (~90000 bytes)
SHA-25628ed8c37320853479bb4f62878c18ed5deae8f3ef82fb29aaae5a26a1deef0c8
MaleculeTh
Evidence
⋯3 more rows
0xa06049000000000000000000000000000000I...............
0xa0704d5a90000300000004000000ffff0000MZ..............
0xa080b8000000000000004000000000000000........@.......
0xa09000000000000000000000000000000000................
⋯7 more rows
⋯7 more rows
0x19388fcd20010000000002e50414400000000.........PAD....
0x1939852656753657456616c75654578287374RegSetValueEx(st
0x193a861727429000000005479706500000000art)....Type....
0x193b853595354454d5c43757272656e74436fSYSTEM\CurrentCo
⋯15 more rows