SHA1
- 4b4621365aedb32cfcc1584b37444070a4a5d5c1
- be16d6dfe96b0d9e2d57882840eabf4f46a37e2c
Detection for the system of remote administration with an open source code which is known as Gh0st RAT. It is installed on the computer by Trojan.BtcMine.1259.
Checks the value of the fourth argument sent to the function. Allowed values are “DhlVipVersfs” and “DhlMemVersgt”, if the function sends any other value, the backdoor shuts itself down.