General

  • Target

    9a3cb53d8dc9aaa1b055d62e89020e9981547c7edf9b286f3e9308e3872d0625

  • Size

    899KB

  • Sample

    240705-dlekxstcrh

  • MD5

    de9becdf29e7e21ec80fce72962083ff

  • SHA1

    6cd0fe559ac67b48e9a9f9f49d9350ae8c091d68

  • SHA256

    9a3cb53d8dc9aaa1b055d62e89020e9981547c7edf9b286f3e9308e3872d0625

  • SHA512

    7db3390cf84c53583fe1ff003ea071e51bc8907ae02b749a5b7694267910dbf256a54e5f07f626daaa05068d15cff97b4224b96d1a6bb9b2fb8d58f8bf2698f3

  • SSDEEP

    24576:7V2bG+2gMir4fgt7ibhRM5QhKehFdMtRj7nH1PXf:7wqd87Vf

Score
10/10

Malware Config

Extracted

Family

gh0strat

C2

hackerinvasion.f3322.net

Targets

    • Target

      9a3cb53d8dc9aaa1b055d62e89020e9981547c7edf9b286f3e9308e3872d0625

    • Size

      899KB

    • MD5

      de9becdf29e7e21ec80fce72962083ff

    • SHA1

      6cd0fe559ac67b48e9a9f9f49d9350ae8c091d68

    • SHA256

      9a3cb53d8dc9aaa1b055d62e89020e9981547c7edf9b286f3e9308e3872d0625

    • SHA512

      7db3390cf84c53583fe1ff003ea071e51bc8907ae02b749a5b7694267910dbf256a54e5f07f626daaa05068d15cff97b4224b96d1a6bb9b2fb8d58f8bf2698f3

    • SSDEEP

      24576:7V2bG+2gMir4fgt7ibhRM5QhKehFdMtRj7nH1PXf:7wqd87Vf

    Score
    10/10
    • Gh0st RAT payload

    • Gh0strat

      Gh0st RAT is a remote access tool (RAT) with its source code public and it has been used by multiple Chinese groups.

MITRE ATT&CK Matrix

Tasks