Suspicious 80% Download

Trojan.Win32.Dialer.jw

Signed dialer trojan

File changed after it was signedAuthenticode chain CN: Comforest SRL
SHA-2564d36dfcd5db44209e9d14effc49ef7c459c4e72923b68004b80dc2360488488f

Evidence

File changed after it was signed 0x0–0x50
0x04d5a90000300000004000000ffff0000MZ..............
0x10b8000000000000004000000000000000........@.......
0x2000000000000000000000000000000000................
⋯3 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.