Hostile 92% Download

Trojan-GameThief.Win32.OnLineGames.bkvu

GameThief trojan with embedded PE

Detects Gh0st RAT mentioned in Cylance' Ghost Dragon ReportEmbedded PE binary at file offset 0xa070 (~90000 bytes)
SHA-25628ed8c37320853479bb4f62878c18ed5deae8f3ef82fb29aaae5a26a1deef0c8
MaleculeTh

Evidence

Embedded PE binary at file offset 0xa070 (~90000 bytes) 0xa030–0xa100
⋯3 more rows
0xa06049000000000000000000000000000000I...............
0xa0704d5a90000300000004000000ffff0000MZ..............
0xa080b8000000000000004000000000000000........@.......
0xa09000000000000000000000000000000000................
⋯7 more rows
Detects Gh0st RAT mentioned in Cylance' Ghost Dragon Report 0x19318–0x194a8
⋯7 more rows
0x19388fcd20010000000002e50414400000000.........PAD....
0x1939852656753657456616c75654578287374RegSetValueEx(st
0x193a861727429000000005479706500000000art)....Type....
0x193b853595354454d5c43757272656e74436fSYSTEM\CurrentCo
⋯15 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.