General
-
Target
8500bf54b8f7229a05b72a352166448070cca37261eac5d316c4116210bb914c
-
Size
2.0MB
-
Sample
240701-ezp49awdpb
-
MD5
c37ec28ac7d470aec71fbf5292cc29af
-
SHA1
bcaea4cd253a461bccde525a98a786b0fa1727c9
-
SHA256
8500bf54b8f7229a05b72a352166448070cca37261eac5d316c4116210bb914c
-
SHA512
7edcdafdd29f653a96e9d1da440769d4c17a91afb494f963da714273a05dc5d60e0ae1cbc460412ca09a3a59536647bd48557a829f93b62da94298eacde4cb7e
-
SSDEEP
49152:zQZAdVyVT9n/Gg0P+WhozpeLEZPItx2apeapelI:0GdVyVT9nOgmhDLltUvlI
Static task
static1
Behavioral task
behavioral1
Sample
8500bf54b8f7229a05b72a352166448070cca37261eac5d316c4116210bb914c.exe
Resource
win7-20240611-en
Malware Config
Targets
-
-
Target
8500bf54b8f7229a05b72a352166448070cca37261eac5d316c4116210bb914c
-
Size
2.0MB
-
MD5
c37ec28ac7d470aec71fbf5292cc29af
-
SHA1
bcaea4cd253a461bccde525a98a786b0fa1727c9
-
SHA256
8500bf54b8f7229a05b72a352166448070cca37261eac5d316c4116210bb914c
-
SHA512
7edcdafdd29f653a96e9d1da440769d4c17a91afb494f963da714273a05dc5d60e0ae1cbc460412ca09a3a59536647bd48557a829f93b62da94298eacde4cb7e
-
SSDEEP
49152:zQZAdVyVT9n/Gg0P+WhozpeLEZPItx2apeapelI:0GdVyVT9nOgmhDLltUvlI
-
Gh0st RAT payload
-
Drops file in Drivers directory
-
Server Software Component: Terminal Services DLL
-
Sets service image path in registry
-
Executes dropped EXE
-
Loads dropped DLL
-
Drops file in System32 directory
-