Trojan.Win32.Dialer.dxj
Trojan with embedded PE
Detects Gh0st RAT mentioned in Cylance' Ghost Dragon ReportEmbedded PE binary at file offset 0x14660 (~8096 bytes)
SHA-256ef2e1df7819658ca4cc952bbb4f009086575bbc8321c5bc639036b77297f777c
MaleculeMdTh
Evidence
⋯9 more rows
0xf340b851130e8f3bd10fd685970de1ef550c.Q...;........U.
0xf35064f91a095393d8080a2d9e0a3d475c0bd...S....-..=G\.
0xf36070a3261c47c9e41d1e77a21f291d601ep.&.G....w..).`.
⋯9 more rows
0x12770486f6f6b45784100ae02556e686f6f6bHookExA...Unhook
0x1278057696e646f7773486f6f6b4578003b02WindowsHookEx.;.
0x1279053656e644d6573736167654100009902SendMessageA....
0x127a053797374656d506172616d6574657273SystemParameters
0x127b0496e666f4100d5026b657962645f6576InfoA...keybd_ev
0x127c0656e7400d6014d61705669727475616cent...MapVirtual
⋯5 more rows
⋯7 more rows
0x137704572726f72436f6e74726f6c00000000ErrorControl....
0x1378052656753657456616c75654578287374RegSetValueEx(st
0x1379061727429000000005479706500000000art)....Type....
0x137a052656753657456616c75654578287374RegSetValueEx(st
⋯22 more rows
⋯3 more rows
0x139ec740000005c7379736c6f672e64617400t...\syslog.dat.
0x139fc0d0a5b253032642f253032642f256420..[%02d/%02d/%d
0x13a0c253032643a253032643a253032645d20%02d:%02d:%02d]
0x13a1c282573290d0a00000d0a00005d000000(%s)........]...
⋯7 more rows
⋯3 more rows
0x1465000000000000000000300420049004e00..........B.I.N.
0x146604d5a90000300000004000000ffff0000MZ..............
0x14670b8000000000000004000000000000000........@.......
0x1468000000000000000000000000000000000................
⋯7 more rows