MalwareBazaar Database

This page shows some basic information the YARA rule EXE_gh0st_RootKit_first_stage_March2024 including corresponding malware samples.

Database Entry


YARA Rule:EXE_gh0st_RootKit_first_stage_March2024
Author:Yashraj Solanki - Cyber Threat Intelligence Analyst at Bridewell
Description:Detects gh0st Root Kit malware Dropper which contains an embedded second stage payload based on PE properties
Firstseen:2026-09-14 12:15:09 UTC
Lastseen:never
Sightings:1

Malware Samples


The table below shows all malware samples that matching this particular YARA rule (max 1000).

Firstseen (UTC)SHA256 hashTagsSignatureReporter