Trojan-PSW.Win32.LdPinch.yhm
Named Trojan, embedded PE
Detects executables referencing many file transfer clients. Observed in information stealersTiny PE by file size
SHA-256ab73c11b4dced65bc07e80804f7dff81af56ba05f9053808befbd1f88dca230d
MaleculeTh
Evidence
⋯7 more rows
0x94d064657220585000536f6674776172655cder XP.Software\
0x94e0476869736c65725c57696e646f777320Ghisler\Windows
0x94f0436f6d6d616e64657200536f66747761Commander.Softwa
0x950072655c476869736c65725c546f74616cre\Ghisler\Total
0x951020436f6d6d616e646572005c50726f66 Commander.\Prof
0x9520696c65735c50726f665c005c50726f66iles\Prof\.\Prof
⋯15 more rows
⋯3 more rows
0x9b4e5c736f7572636566696c652e64617400\sourcefile.dat.
0x9b5e4d5a90000300000004000000ffff0000MZ..............
0x9b6eb8000000000000004000000000000000........@.......
0x9b7e00000000000000000000000000000000................
⋯7 more rows
⋯7 more rows
0x94d064657220585000536f6674776172655cder XP.Software\
0x94e0476869736c65725c57696e646f777320Ghisler\Windows
0x94f0436f6d6d616e64657200536f66747761Commander.Softwa
0x950072655c476869736c65725c546f74616cre\Ghisler\Total
0x951020436f6d6d616e646572005c50726f66 Commander.\Prof
0x9520696c65735c50726f665c005c50726f66iles\Prof\.\Prof
⋯15 more rows
⋯3 more rows
0x9b4e5c736f7572636566696c652e64617400\sourcefile.dat.
0x9b5e4d5a90000300000004000000ffff0000MZ..............
0x9b6eb8000000000000004000000000000000........@.......
0x9b7e00000000000000000000000000000000................
⋯7 more rows
⋯3 more rows
0x30000000000000000000000000c0000000................
0x400e1fba0e00b409cd21b8014ccd215468........!..L.!Th
0x5069732070726f6772616d2063616e6e6fis program canno
⋯6 more rows