General

  • Target

    7c9c1c1c92dd3e15319d809eec02e23d9b047d165fc2572ebe883c3eb8010198

  • Size

    899KB

  • Sample

    240701-ezp49awdpa

  • MD5

    db532b52369b3789aaed92f529379cf4

  • SHA1

    393b776b5405c310d29f7715235043f6cf40fead

  • SHA256

    7c9c1c1c92dd3e15319d809eec02e23d9b047d165fc2572ebe883c3eb8010198

  • SHA512

    a4949f198d542525681b59861ea8d2d73ddb61f1862311fd1790a43506e6984b74d4d056b87fdf6dc4c5161f0561e83e979d6308b642d6d2dfd6504bf8bcf26c

  • SSDEEP

    24576:7V2bG+2gMir4fgt7ibhRM5QhKehFdMtRj7nH1PXk:7wqd87Vk

Score
10/10

Malware Config

Extracted

Family

gh0strat

C2

hackerinvasion.f3322.net

Targets

    • Target

      7c9c1c1c92dd3e15319d809eec02e23d9b047d165fc2572ebe883c3eb8010198

    • Size

      899KB

    • MD5

      db532b52369b3789aaed92f529379cf4

    • SHA1

      393b776b5405c310d29f7715235043f6cf40fead

    • SHA256

      7c9c1c1c92dd3e15319d809eec02e23d9b047d165fc2572ebe883c3eb8010198

    • SHA512

      a4949f198d542525681b59861ea8d2d73ddb61f1862311fd1790a43506e6984b74d4d056b87fdf6dc4c5161f0561e83e979d6308b642d6d2dfd6504bf8bcf26c

    • SSDEEP

      24576:7V2bG+2gMir4fgt7ibhRM5QhKehFdMtRj7nH1PXk:7wqd87Vk

    Score
    10/10
    • Gh0st RAT payload

    • Gh0strat

      Gh0st RAT is a remote access tool (RAT) with its source code public and it has been used by multiple Chinese groups.

MITRE ATT&CK Matrix

Tasks