General

  • Target

    b8cfdf394518682b1d6e37a71a99f6aa43af1d6f32395e6e803b8f74f99ad3c4

  • Size

    50KB

  • Sample

    240701-apavcszglc

  • MD5

    463b8c38f7f1d82c980c183497bdd0b2

  • SHA1

    6c080cc5cb1fcbb34fa0d6f70b3724aea9dba593

  • SHA256

    b8cfdf394518682b1d6e37a71a99f6aa43af1d6f32395e6e803b8f74f99ad3c4

  • SHA512

    bbade7c25ac4316d42d4d8b70343007e6e67a5e100902da6a2e517d05212c4068da885cbd7b24abe408004374b11a486452253b86ddc113688f5176f99e0e953

  • SSDEEP

    1536:WD1N4TeeWMWfPbp2WTrW9L3JPPgJ+o56JYH:W5ReWjTrW9rNPgYo4JYH

Score
10/10

Malware Config

Extracted

Family

gh0strat

C2

hackerinvasion.f3322.net

Targets

    • Target

      b8cfdf394518682b1d6e37a71a99f6aa43af1d6f32395e6e803b8f74f99ad3c4

    • Size

      50KB

    • MD5

      463b8c38f7f1d82c980c183497bdd0b2

    • SHA1

      6c080cc5cb1fcbb34fa0d6f70b3724aea9dba593

    • SHA256

      b8cfdf394518682b1d6e37a71a99f6aa43af1d6f32395e6e803b8f74f99ad3c4

    • SHA512

      bbade7c25ac4316d42d4d8b70343007e6e67a5e100902da6a2e517d05212c4068da885cbd7b24abe408004374b11a486452253b86ddc113688f5176f99e0e953

    • SSDEEP

      1536:WD1N4TeeWMWfPbp2WTrW9L3JPPgJ+o56JYH:W5ReWjTrW9rNPgYo4JYH

    Score
    10/10
    • Gh0st RAT payload

    • Gh0strat

      Gh0st RAT is a remote access tool (RAT) with its source code public and it has been used by multiple Chinese groups.

MITRE ATT&CK Matrix

Tasks