General

  • Target

    1715305202af4fe691c0fede48ca69c6516c88d9e92c6bae6116ea3a8da6b3c9

  • Size

    51KB

  • Sample

    240630-2al3maxdra

  • MD5

    1d0e3fc03382fe0f0d4bbe16e2305bd0

  • SHA1

    2eec72306c556497f83001775ac2d2233fd51dcb

  • SHA256

    1715305202af4fe691c0fede48ca69c6516c88d9e92c6bae6116ea3a8da6b3c9

  • SHA512

    95798276fa49406c14e91dfb3769bcf5633fe1fe512d8a5ef2e66461ccf632b27435ae9a9fc0f54220ff2283656431c5757eb67b5a1c7740292496c088f037e1

  • SSDEEP

    1536:1WmqoiBMNbMWtYNif/n9S91BF3frnoLZJYH5:1dWubF3n9S91BF3fbodJYH5

Score
10/10

Malware Config

Extracted

Family

gh0strat

C2

kinh.xmcxmr.com

Targets

    • Target

      1715305202af4fe691c0fede48ca69c6516c88d9e92c6bae6116ea3a8da6b3c9

    • Size

      51KB

    • MD5

      1d0e3fc03382fe0f0d4bbe16e2305bd0

    • SHA1

      2eec72306c556497f83001775ac2d2233fd51dcb

    • SHA256

      1715305202af4fe691c0fede48ca69c6516c88d9e92c6bae6116ea3a8da6b3c9

    • SHA512

      95798276fa49406c14e91dfb3769bcf5633fe1fe512d8a5ef2e66461ccf632b27435ae9a9fc0f54220ff2283656431c5757eb67b5a1c7740292496c088f037e1

    • SSDEEP

      1536:1WmqoiBMNbMWtYNif/n9S91BF3frnoLZJYH5:1dWubF3n9S91BF3fbodJYH5

    Score
    10/10
    • Gh0st RAT payload

    • Gh0strat

      Gh0st RAT is a remote access tool (RAT) with its source code public and it has been used by multiple Chinese groups.

MITRE ATT&CK Matrix

Tasks