Trojan.Win32.Dialer.cdk
Trojan with embedded PE payload
Detects Gh0st RAT mentioned in Cylance' Ghost Dragon ReportEmbedded PE binary at file offset 0x14460 (~2944 bytes)
SHA-256aae9ea8efadf0ff8178fe1c5fa29e932065d88530e8b5b7f62d2779f3291a67f
MaleculeMdTh
Evidence
⋯7 more rows
0x1033c0000000000000000e91c001020059319............ ...
0x1034c01000000681301100000000000000000....h...........
0x1035c000000000000000000000000ffffffff................
⋯11 more rows
0x113f4457800008a0253657457696e646f7773Ex....SetWindows
0x11404486f6f6b45784100ae02556e686f6f6bHookExA...Unhook
0x1141457696e646f7773486f6f6b4578009902WindowsHookEx...
0x1142453797374656d506172616d6574657273SystemParameters
0x11434496e666f41003b0253656e644d657373InfoA.;.SendMess
0x11444616765410000d6026b657962645f6576ageA....keybd_ev
⋯5 more rows
⋯7 more rows
0x123fc53746172740000005479706500000000Start...Type....
0x1240c52656753657456616c75654578287374RegSetValueEx(st
0x1241c61727429000000004572726f72436f6eart)....ErrorCon
0x1242c74726f6c000000004f626a6563744e61trol....ObjectNa
⋯18 more rows
⋯3 more rows
0x125a4700000005c757365722e646174000000p...\user.dat...
0x125b40d0a5b253032642f253032642f256420..[%02d/%02d/%d
0x125c4253032643a253032643a253032645d20%02d:%02d:%02d]
0x125d4282573290d0a00005d0000000d0a0000(%s)....].......
⋯7 more rows
⋯3 more rows
0x1445000000000000000000300420049004e00..........B.I.N.
0x144604d5a90000300000004000000ffff0000MZ..............
0x14470b8000000000000004000000000000000........@.......
0x1448000000000000000000000000000000000................
⋯7 more rows