Trojan.Win32.Dialer.udu
Trojan with embedded PE payload
Detects Gh0st RAT mentioned in Cylance' Ghost Dragon ReportEmbedded PE binary at file offset 0x166c0 (~10083 bytes)
SHA-256cfee94dbd05cabcf706f440eae76ac7e625be28a946cfb16bd27ac09fcc83916
MaleculeMdTh
Evidence
⋯6 more rows
0x123b81a1a1a1a1a1a1a1a1b1b1b1b1b1b1b1b................
0x123c81b1b1b1b1b1b1b1b1b1b1b1b1b1b1b1b................
0x123d81b1b1b1b1b1b1b1c0000000001000000................
⋯7 more rows
0x13fea0000ba014c6f6164437572736f724100....LoadCursorA.
0x13ffa950044657374726f79437572736f7200..DestroyCursor.
0x1400a0e00426c6f636b496e70757400009902..BlockInput....
0x1401a53797374656d506172616d6574657273SystemParameters
0x1402a496e666f4100d5026b657962645f6576InfoA...keybd_ev
0x1403a656e7400d6014d61705669727475616cent...MapVirtual
⋯5 more rows
⋯7 more rows
0x14c3c4578706c6f7265722e65786500000000Explorer.exe....
0x14c4c4d6f7a696c6c612f342e302028636f6dMozilla/4.0 (com
0x14c5c70617469626c6529000000005c636d64patible)....\cmd
0x14c6c2e657865000000004142434445464748.exe....ABCDEFGH
⋯18 more rows
⋯3 more rows
0x14f00616b00004f2e646c6c0000005c000000ak..O.dll...\...
0x14f100d0a5b253032642f253032642f256420..[%02d/%02d/%d
0x14f20253032643a253032643a253032645d20%02d:%02d:%02d]
0x14f30282573290d0a00005d0000000d0a0000(%s)....].......
⋯3 more rows
0x14f70e8320110000000002e50414400000000.2.......PAD....
0x14f8052656753657456616c75654578287374RegSetValueEx(st
0x14f9061727429000000005479706500000000art)....Type....
0x14fa053595354454d5c43757272656e74436fSYSTEM\CurrentCo
⋯15 more rows
⋯3 more rows
0x166b05f005300590053000000000000000000_.S.Y.S.........
0x166c04d5a90000300000004000000ffff0000MZ..............
0x166d0b8000000000000004000000000000000........@.......
0x166e000000000000000000000000000000000................
⋯7 more rows