Benign download unavailable

Trojan.Win32.Dialer.brd

Detects Gh0st RAT mentioned in Cylance' Ghost Dragon ReportEmbedded PE binary at file offset 0x16060 (~2944 bytes)
SHA-25633b6bda3402228c525e725ab084092107b39e9246c49239835a19758ded1d3ae
MaleculeMdTh

Evidence

Query/set system parameters (symbol) 0x122f8–0x12498
⋯11 more rows
0x123a838500100e02301009c400100000000008P...#...@......
0x123b8000000004250010024240100a03e0100....BP..$$...>..
0x123c800000000000000003c53010028220100........<S..("..
⋯13 more rows
Query/set system parameters (string) 0x12fea–0x1308a
0x12fea7800b7014c6f6164437572736f724100x...LoadCursorA.
0x12ffa950044657374726f79437572736f7200..DestroyCursor.
0x1300a0e00426c6f636b496e70757400009902..BlockInput....
0x1301a53797374656d506172616d6574657273SystemParameters
0x1302a496e666f41003b0253656e644d657373InfoA.;.SendMess
0x1303a616765410000d6026b657962645f6576ageA....keybd_ev
⋯5 more rows
Detects Gh0st RAT mentioned in Cylance' Ghost Dragon Report 0x13f8c–0x1414c
⋯7 more rows
0x13ffc53746172740000005479706500000000Start...Type....
0x1400c52656753657456616c75654578287374RegSetValueEx(st
0x1401c61727429000000004572726f72436f6eart)....ErrorCon
0x1402c74726f6c000000004f626a6563744e61trol....ObjectNa
⋯18 more rows
Percent-encoded content decoded 0x14174–0x14244
⋯3 more rows
0x141a4700000005c757365722e646174000000p...\user.dat...
0x141b40d0a5b253032642f253032642f256420..[%02d/%02d/%d
0x141c4253032643a253032643a253032645d20%02d:%02d:%02d]
0x141d4282573290d0a00005d0000000d0a0000(%s)....].......
⋯7 more rows
Embedded PE binary at file offset 0x16060 (~2944 bytes) 0x16020–0x160f0
⋯3 more rows
0x1605000000000000000000300420049004e00..........B.I.N.
0x160604d5a90000300000004000000ffff0000MZ..............
0x16070b8000000000000004000000000000000........@.......
0x1608000000000000000000000000000000000................
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.