MalwareBazaar Database

This page shows some basic information the YARA rule win_ghostsocks_auto including corresponding malware samples.

Database Entry


YARA Rule:win_ghostsocks_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.ghostsocks.
Firstseen:2024-12-24 07:35:43 UTC
Lastseen:2025-10-07 12:03:54 UTC
Sightings:17

Malware Samples


The table below shows all malware samples that matching this particular YARA rule (max 1000).

Firstseen (UTC)SHA256 hashTagsSignatureReporter