General

  • Target

    f89c33c8ec9282d84f5b9402c4f0b9fc863407e2ab0a2b8b34da6460ae6e16e2

  • Size

    899KB

  • Sample

    240701-ezptgswdne

  • MD5

    936d9cc9efcb071731f61785cb8bbafd

  • SHA1

    4f8f0dc6dca833f1bf5f842d238aedb3a7a20e7f

  • SHA256

    f89c33c8ec9282d84f5b9402c4f0b9fc863407e2ab0a2b8b34da6460ae6e16e2

  • SHA512

    db483f0fd232c456fc75a6c4066af07fa78fa27c1278d1e9ff6fdf45e8d0ff2b99f85b09cbb103f9534a0e52f8cc0e12ec43cb330ae2b723c3e5b332a64719b7

  • SSDEEP

    24576:7V2bG+2gMir4fgt7ibhRM5QhKehFdMtRj7nH1PXT:7wqd87VT

Score
10/10

Malware Config

Extracted

Family

gh0strat

C2

hackerinvasion.f3322.net

Targets

    • Target

      f89c33c8ec9282d84f5b9402c4f0b9fc863407e2ab0a2b8b34da6460ae6e16e2

    • Size

      899KB

    • MD5

      936d9cc9efcb071731f61785cb8bbafd

    • SHA1

      4f8f0dc6dca833f1bf5f842d238aedb3a7a20e7f

    • SHA256

      f89c33c8ec9282d84f5b9402c4f0b9fc863407e2ab0a2b8b34da6460ae6e16e2

    • SHA512

      db483f0fd232c456fc75a6c4066af07fa78fa27c1278d1e9ff6fdf45e8d0ff2b99f85b09cbb103f9534a0e52f8cc0e12ec43cb330ae2b723c3e5b332a64719b7

    • SSDEEP

      24576:7V2bG+2gMir4fgt7ibhRM5QhKehFdMtRj7nH1PXT:7wqd87VT

    Score
    10/10
    • Gh0st RAT payload

    • Gh0strat

      Gh0st RAT is a remote access tool (RAT) with its source code public and it has been used by multiple Chinese groups.

MITRE ATT&CK Matrix

Tasks