General

  • Target

    6fabfaf63b4771c9086678e7967f1b67f492436951dcf2686a675079a5db224e

  • Size

    51KB

  • Sample

    240630-2cc8haxelg

  • MD5

    d8dce6591310078c06213790353f59c3

  • SHA1

    ddde0b05a9c67948bf2fb42b9081f0ca2d06caf4

  • SHA256

    6fabfaf63b4771c9086678e7967f1b67f492436951dcf2686a675079a5db224e

  • SHA512

    d7a1449e90af85b50e1f9b4a0f6b72385cc00d943740db59851270b58dfbeb5b1f7b9eb44e4c772672710008c4288dbc1ac983e26ef66cddd3e24da6b6eb4a8f

  • SSDEEP

    1536:1WmqoiBMNbMWtYNif/n9S91BF3frnoLbJYH5:1dWubF3n9S91BF3fbonJYH5

Score
10/10

Malware Config

Extracted

Family

gh0strat

C2

kinh.xmcxmr.com

Targets

    • Target

      6fabfaf63b4771c9086678e7967f1b67f492436951dcf2686a675079a5db224e

    • Size

      51KB

    • MD5

      d8dce6591310078c06213790353f59c3

    • SHA1

      ddde0b05a9c67948bf2fb42b9081f0ca2d06caf4

    • SHA256

      6fabfaf63b4771c9086678e7967f1b67f492436951dcf2686a675079a5db224e

    • SHA512

      d7a1449e90af85b50e1f9b4a0f6b72385cc00d943740db59851270b58dfbeb5b1f7b9eb44e4c772672710008c4288dbc1ac983e26ef66cddd3e24da6b6eb4a8f

    • SSDEEP

      1536:1WmqoiBMNbMWtYNif/n9S91BF3frnoLbJYH5:1dWubF3n9S91BF3fbonJYH5

    Score
    10/10
    • Gh0st RAT payload

    • Gh0strat

      Gh0st RAT is a remote access tool (RAT) with its source code public and it has been used by multiple Chinese groups.

MITRE ATT&CK Matrix

Tasks