Trojan-GameThief.Win32.Magania.arwp
Detects Gh0st RAT mentioned in Cylance' Ghost Dragon ReportEmbedded PE binary at file offset 0x2a60 (~97315 bytes)
SHA-25661d6d29c40b4e818756e7f8a20917dd38208900263f33b0974d8bd0576a2fddf
MaleculeMdTh
Evidence
⋯3 more rows
0x2a5000000000000000000300420049004e00..........B.I.N.
0x2a604d5a90000300000004000000ffff0000MZ..............
0x2a70b8000000000000004000000000000000........@.......
0x2a8000000000000000000000000000000000................
⋯7 more rows
0x15f2a7800b7014c6f6164437572736f724100x...LoadCursorA.
0x15f3a950044657374726f79437572736f7200..DestroyCursor.
0x15f4a0e00426c6f636b496e70757400009902..BlockInput....
0x15f5a53797374656d506172616d6574657273SystemParameters
0x15f6a496e666f41003b0253656e644d657373InfoA.;.SendMess
0x15f7a616765410000d6026b657962645f6576ageA....keybd_ev
⋯5 more rows
⋯7 more rows
0x1705c53746172740000005479706500000000Start...Type....
0x1706c52656753657456616c75654578287374RegSetValueEx(st
0x1707c61727429000000004572726f72436f6eart)....ErrorCon
0x1708c74726f6c000000004f626a6563744e61trol....ObjectNa
⋯18 more rows
⋯3 more rows
0x1720c722e64617400000025642e62616b0000r.dat...%d.bak..
0x1721c0d0a5b253032642f253032642f256420..[%02d/%02d/%d
0x1722c253032643a253032643a253032645d20%02d:%02d:%02d]
0x1723c282573290d0a00005d0000000d0a0000(%s)....].......
⋯18 more rows