General

  • Target

    5f064c9a4c17fe521479de026ce56f84519b5ff1d6628f1044b55cb757e91e20

  • Size

    51KB

  • Sample

    240630-2ef26sxere

  • MD5

    f5da20dce4e30c716cac87c2bfba5f6a

  • SHA1

    6f005586a9d3dd809f713d16dd6502bf028f79c9

  • SHA256

    5f064c9a4c17fe521479de026ce56f84519b5ff1d6628f1044b55cb757e91e20

  • SHA512

    0dfd0f50728e0316a7a31348559cba876ef5dd919b1f042d957cef18b13a1c6c23c451033e342faaa1ae7bfadc022e1be0df91ecbda18ec1f266583b2f4b2b90

  • SSDEEP

    1536:1WmqoiBMNbMWtYNif/n9S91BF3frnoL+AJYH5:1dWubF3n9S91BF3fbo7JYH5

Score
10/10

Malware Config

Extracted

Family

gh0strat

C2

kinh.xmcxmr.com

Targets

    • Target

      5f064c9a4c17fe521479de026ce56f84519b5ff1d6628f1044b55cb757e91e20

    • Size

      51KB

    • MD5

      f5da20dce4e30c716cac87c2bfba5f6a

    • SHA1

      6f005586a9d3dd809f713d16dd6502bf028f79c9

    • SHA256

      5f064c9a4c17fe521479de026ce56f84519b5ff1d6628f1044b55cb757e91e20

    • SHA512

      0dfd0f50728e0316a7a31348559cba876ef5dd919b1f042d957cef18b13a1c6c23c451033e342faaa1ae7bfadc022e1be0df91ecbda18ec1f266583b2f4b2b90

    • SSDEEP

      1536:1WmqoiBMNbMWtYNif/n9S91BF3frnoL+AJYH5:1dWubF3n9S91BF3fbo7JYH5

    Score
    10/10
    • Gh0st RAT payload

    • Gh0strat

      Gh0st RAT is a remote access tool (RAT) with its source code public and it has been used by multiple Chinese groups.

MITRE ATT&CK Matrix

Tasks