General

  • Target

    1a97c21ab895158257adf055ccd6cf3e_JaffaCakes118

  • Size

    126KB

  • Sample

    240701-kblpta1epd

  • MD5

    1a97c21ab895158257adf055ccd6cf3e

  • SHA1

    5697ad1e9878370ea1f5db00e85298409d489e2b

  • SHA256

    c792acee0987ac17474c1dc846b0c0a1ae2a81a7f08151ffab2754d96085c5cd

  • SHA512

    d58d6ed83d30a94359cfef3605c08d921ad49c5b64ef4def8a1c2d883a83ef2d17f12958630738bf2105f9aa9b9c786b87bb19557efb01811c7eec4045f0e510

  • SSDEEP

    3072:41UNGB+I0Oy8uIqn904rKttHkoIIuZkfiXqCYNg:41UQpu8Hqm4wKodkkqXBm

Score
10/10

Malware Config

Targets

    • Target

      1a97c21ab895158257adf055ccd6cf3e_JaffaCakes118

    • Size

      126KB

    • MD5

      1a97c21ab895158257adf055ccd6cf3e

    • SHA1

      5697ad1e9878370ea1f5db00e85298409d489e2b

    • SHA256

      c792acee0987ac17474c1dc846b0c0a1ae2a81a7f08151ffab2754d96085c5cd

    • SHA512

      d58d6ed83d30a94359cfef3605c08d921ad49c5b64ef4def8a1c2d883a83ef2d17f12958630738bf2105f9aa9b9c786b87bb19557efb01811c7eec4045f0e510

    • SSDEEP

      3072:41UNGB+I0Oy8uIqn904rKttHkoIIuZkfiXqCYNg:41UQpu8Hqm4wKodkkqXBm

    Score
    10/10
    • Gh0st RAT payload

    • Gh0strat

      Gh0st RAT is a remote access tool (RAT) with its source code public and it has been used by multiple Chinese groups.

    • Deletes itself

    • Loads dropped DLL

MITRE ATT&CK Matrix

Tasks