General

  • Target

    2b26ce77a2e6e514bd0a9f86c47bb726f97b5a40e89754c393da5df1dca2afae

  • Size

    4.3MB

  • Sample

    240701-e8ygzswfqg

  • MD5

    576593affb4c49d46466f58e617d3be7

  • SHA1

    d3b9288e85a5e5a69209de10f20837153446be24

  • SHA256

    2b26ce77a2e6e514bd0a9f86c47bb726f97b5a40e89754c393da5df1dca2afae

  • SHA512

    346b04b554615e5bb4afef83df4498bbfcc9001c5d6179e6ef611c898e1742d1e521bb37170c10cfa0dbf4a5565c07680536d614ef8b21c8b75a49a411b802b1

  • SSDEEP

    98304:92SVMD8unlE3SfhUtKnUytb70vu5BteBb:1EnlEC+tKUyx0vWteBb

Malware Config

Targets

    • Target

      2b26ce77a2e6e514bd0a9f86c47bb726f97b5a40e89754c393da5df1dca2afae

    • Size

      4.3MB

    • MD5

      576593affb4c49d46466f58e617d3be7

    • SHA1

      d3b9288e85a5e5a69209de10f20837153446be24

    • SHA256

      2b26ce77a2e6e514bd0a9f86c47bb726f97b5a40e89754c393da5df1dca2afae

    • SHA512

      346b04b554615e5bb4afef83df4498bbfcc9001c5d6179e6ef611c898e1742d1e521bb37170c10cfa0dbf4a5565c07680536d614ef8b21c8b75a49a411b802b1

    • SSDEEP

      98304:92SVMD8unlE3SfhUtKnUytb70vu5BteBb:1EnlEC+tKUyx0vWteBb

    • Gh0st RAT payload

    • Gh0strat

      Gh0st RAT is a remote access tool (RAT) with its source code public and it has been used by multiple Chinese groups.

    • Server Software Component: Terminal Services DLL

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Server Software Component

1
T1505

Terminal Services DLL

1
T1505.005

Discovery

System Information Discovery

1
T1082

Tasks