MalwareBazaar Database
This page shows some basic information the YARA rule EXE_gh0st_RootKit_first_stage_March2024 including corresponding malware samples.
Database Entry
| YARA Rule: | EXE_gh0st_RootKit_first_stage_March2024 |
|---|---|
| Author: | Yashraj Solanki - Cyber Threat Intelligence Analyst at Bridewell |
| Description: | Detects gh0st Root Kit malware Dropper which contains an embedded second stage payload based on PE properties |
| Firstseen: | 2026-09-14 12:15:09 UTC |
| Lastseen: | never |
| Sightings: | 1 |
Malware Samples
The table below shows all malware samples that matching this particular YARA rule (max 1000).
| Firstseen (UTC) | SHA256 hash | Tags | Signature | Reporter |
|---|