Benign Download

Trojan-Dropper.Win32.Agent.txc

Detects Gh0st RAT mentioned in Cylance' Ghost Dragon ReportEmbedded PE binary at file offset 0x1460 (~114688 bytes)
SHA-2566c3fd03ce858f30843554564c01f6490b9a7fabd9304503fe63ecc1b252afef1
MaleculeMdTh

Evidence

Embedded PE binary at file offset 0x1460 (~114688 bytes) 0x1420–0x14f0
⋯3 more rows
0x145000000000000000000300420049004e00..........B.I.N.
0x14604d5a90000300000004000000ffff0000MZ..............
0x1470b8000000000000004000000000000000........@.......
0x148000000000000000000000000000000000................
⋯7 more rows
Query/set system parameters (string) 0x1492a–0x149ca
0x1492a7800b7014c6f6164437572736f724100x...LoadCursorA.
0x1493a950044657374726f79437572736f7200..DestroyCursor.
0x1494a0e00426c6f636b496e70757400009902..BlockInput....
0x1495a53797374656d506172616d6574657273SystemParameters
0x1496a496e666f41003b0253656e644d657373InfoA.;.SendMess
0x1497a616765410000d6026b657962645f6576ageA....keybd_ev
⋯5 more rows
Detects Gh0st RAT mentioned in Cylance' Ghost Dragon Report 0x159ec–0x15bac
⋯7 more rows
0x15a5c53746172740000005479706500000000Start...Type....
0x15a6c52656753657456616c75654578287374RegSetValueEx(st
0x15a7c61727429000000004572726f72436f6eart)....ErrorCon
0x15a8c74726f6c000000004f626a6563744e61trol....ObjectNa
⋯18 more rows
Percent-encoded content decoded 0x15bdc–0x15d5c
⋯3 more rows
0x15c0c722e64617400000025642e62616b0000r.dat...%d.bak..
0x15c1c0d0a5b253032642f253032642f256420..[%02d/%02d/%d
0x15c2c253032643a253032643a253032645d20%02d:%02d:%02d]
0x15c3c282573290d0a00005d0000000d0a0000(%s)....].......
⋯18 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.