General

  • Target

    1b26bad6f2f89f4dd63267a54acde9f470d1acc72efb6235c638aaa62a50b122

  • Size

    899KB

  • Sample

    240705-dnq2qstdqh

  • MD5

    f7a75721f7996a0aa038f66705213a5e

  • SHA1

    2419219483066173e924c5414df87e0a09e73b13

  • SHA256

    1b26bad6f2f89f4dd63267a54acde9f470d1acc72efb6235c638aaa62a50b122

  • SHA512

    baa7864a1a38efa0196d1a987b27e95b8e342e2d96e7cf3a001e8715a990098b9c08deb5ac6fde5e7084fcb5852ff06d1ef7ea60e2239e2861f47eb1ba0973f3

  • SSDEEP

    24576:7V2bG+2gMir4fgt7ibhRM5QhKehFdMtRj7nH1PX5:7wqd87V5

Score
10/10

Malware Config

Extracted

Family

gh0strat

C2

hackerinvasion.f3322.net

Targets

    • Target

      1b26bad6f2f89f4dd63267a54acde9f470d1acc72efb6235c638aaa62a50b122

    • Size

      899KB

    • MD5

      f7a75721f7996a0aa038f66705213a5e

    • SHA1

      2419219483066173e924c5414df87e0a09e73b13

    • SHA256

      1b26bad6f2f89f4dd63267a54acde9f470d1acc72efb6235c638aaa62a50b122

    • SHA512

      baa7864a1a38efa0196d1a987b27e95b8e342e2d96e7cf3a001e8715a990098b9c08deb5ac6fde5e7084fcb5852ff06d1ef7ea60e2239e2861f47eb1ba0973f3

    • SSDEEP

      24576:7V2bG+2gMir4fgt7ibhRM5QhKehFdMtRj7nH1PX5:7wqd87V5

    Score
    10/10
    • Gh0st RAT payload

    • Gh0strat

      Gh0st RAT is a remote access tool (RAT) with its source code public and it has been used by multiple Chinese groups.

MITRE ATT&CK Matrix

Tasks