Trojan.Win32.Dialer.azm
Trojan with embedded PE and RAT
Detects Gh0st RAT mentioned in Cylance' Ghost Dragon ReportEmbedded PE binary at file offset 0x2660 (~94112 bytes)
SHA-256e89b6b84b3b3f22d6afd231bdacd2f99a4fcac75cbc03ebd9d0b4601f54bffc2
MaleculeMdTh
Evidence
⋯3 more rows
0x265000000000000000000300420049004e00..........B.I.N.
0x26604d5a90000300000004000000ffff0000MZ..............
0x2670b8000000000000004000000000000000........@.......
0x268000000000000000000000000000000000................
⋯7 more rows
0x147fc7773486f6f6b45784100ae02556e686fwsHookExA...Unho
0x1480c6f6b57696e646f7773486f6f6b457800okWindowsHookEx.
0x1481c0e00426c6f636b496e70757400009902..BlockInput....
0x1482c53797374656d506172616d6574657273SystemParameters
0x1483c496e666f41003b0253656e644d657373InfoA.;.SendMess
0x1484c616765410000d6026b657962645f6576ageA....keybd_ev
⋯5 more rows
⋯7 more rows
0x1585c53746172740000005479706500000000Start...Type....
0x1586c52656753657456616c75654578287374RegSetValueEx(st
0x1587c61727429000000004572726f72436f6eart)....ErrorCon
0x1588c74726f6c000000004f626a6563744e61trol....ObjectNa
⋯15 more rows
⋯3 more rows
0x15a04700000005c757365722e646174000000p...\user.dat...
0x15a140d0a5b253032642f253032642f256420..[%02d/%02d/%d
0x15a24253032643a253032643a253032645d20%02d:%02d:%02d]
0x15a34282573290d0a00005d0000000d0a0000(%s)....].......
⋯7 more rows