Hostile 92% Download

Trojan.Win32.Dialer.cua

RAT, embedded PE, evasion

Detects Gh0st RAT mentioned in Cylance' Ghost Dragon ReportEmbedded PE binary at file offset 0x2660 (~102027 bytes)
SHA-256456d01664997cfcd29cf95d0426d8d3a10c132150fca0c003fe51182cb8fc951
MaleculeMdTh

Evidence

Embedded PE binary at file offset 0x2660 (~102027 bytes) 0x2620–0x26f0
⋯3 more rows
0x265000000000000000000300420049004e00..........B.I.N.
0x26604d5a90000300000004000000ffff0000MZ..............
0x2670b8000000000000004000000000000000........@.......
0x268000000000000000000000000000000000................
⋯7 more rows
Query/set system parameters (string) 0x1564a–0x156ea
0x1564a7800b7014c6f6164437572736f724100x...LoadCursorA.
0x1565a950044657374726f79437572736f7200..DestroyCursor.
0x1566a0e00426c6f636b496e70757400009902..BlockInput....
0x1567a53797374656d506172616d6574657273SystemParameters
0x1568a496e666f41003b0253656e644d657373InfoA.;.SendMess
0x1569a616765410000d6026b657962645f6576ageA....keybd_ev
⋯5 more rows
Detects Gh0st RAT mentioned in Cylance' Ghost Dragon Report 0x165ec–0x167ac
⋯7 more rows
0x1665c53746172740000005479706500000000Start...Type....
0x1666c52656753657456616c75654578287374RegSetValueEx(st
0x1667c61727429000000004572726f72436f6eart)....ErrorCon
0x1668c74726f6c000000004f626a6563744e61trol....ObjectNa
⋯18 more rows
Percent-encoded content decoded 0x167d4–0x168a4
⋯3 more rows
0x16804700000005c757365722e646174000000p...\user.dat...
0x168140d0a5b253032642f253032642f256420..[%02d/%02d/%d
0x16824253032643a253032643a253032645d20%02d:%02d:%02d]
0x16834282573290d0a00005d0000000d0a0000(%s)....].......
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.