General
-
Target
911411bc0725199da39f1aa1046f08dd3c41261b6cad7d2a679bfb1533213d32
-
Size
5.9MB
-
Sample
240704-esc64stern
-
MD5
e3a59bd53715e1322cc0822d051bf792
-
SHA1
f2841033a94bba069ed793cbbce955f138ba0b08
-
SHA256
911411bc0725199da39f1aa1046f08dd3c41261b6cad7d2a679bfb1533213d32
-
SHA512
0d1bc5e4fe0e8d10c59dcffb9d8a9ebf0372a40b1c4c310bde21bfcd08c090dfca97e2e47f35558af428ca10bd9026d04f830642ae20557cd96b11eba7e440a9
-
SSDEEP
98304:9GdVyVT9nOgmh9Dmn2y6666666666666666666666666666666x6666666666663:aWT9nO73mnlu1vZzdDESxkR2Si/eVhzW
Static task
static1
Behavioral task
behavioral1
Sample
911411bc0725199da39f1aa1046f08dd3c41261b6cad7d2a679bfb1533213d32.exe
Resource
win7-20240611-en
Malware Config
Targets
-
-
Target
911411bc0725199da39f1aa1046f08dd3c41261b6cad7d2a679bfb1533213d32
-
Size
5.9MB
-
MD5
e3a59bd53715e1322cc0822d051bf792
-
SHA1
f2841033a94bba069ed793cbbce955f138ba0b08
-
SHA256
911411bc0725199da39f1aa1046f08dd3c41261b6cad7d2a679bfb1533213d32
-
SHA512
0d1bc5e4fe0e8d10c59dcffb9d8a9ebf0372a40b1c4c310bde21bfcd08c090dfca97e2e47f35558af428ca10bd9026d04f830642ae20557cd96b11eba7e440a9
-
SSDEEP
98304:9GdVyVT9nOgmh9Dmn2y6666666666666666666666666666666x6666666666663:aWT9nO73mnlu1vZzdDESxkR2Si/eVhzW
-
Gh0st RAT payload
-
Drops file in Drivers directory
-
Server Software Component: Terminal Services DLL
-
Sets service image path in registry
-
Executes dropped EXE
-
Loads dropped DLL
-
Drops file in System32 directory
-