🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 096d5e1b254aadd10aa5e86735914f4697674018b63c19a150daecdd0690f4a7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gh0stRAT


Vendor detections: 15


Intelligence 15 IOCs YARA 4 File information Comments

SHA256 hash: 096d5e1b254aadd10aa5e86735914f4697674018b63c19a150daecdd0690f4a7
SHA3-384 hash: d25e41f37a060de34bdbe0b1a8ee44ffcee95520f0155ef5978a97c6d8d9fce24568bdd74e245e4aba306c6c3e4a14c9
SHA1 hash: 0183cf76722c7e2ad6ad048c9fc649519f3ff415
MD5 hash: 0da96fa20bcfb5b11e3c87c468bb4f82
humanhash: delta-mississippi-nevada-low
File name:SystemProcessl77.exe
Download: download sample
Signature Gh0stRAT
File size:458'752 bytes
First seen:2025-06-25 19:20:48 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash af30b489fb65b99b524d1090c1c8a07b (1 x Gh0stRAT)
ssdeep 12288:GMlC5MG3Czv64/9fhNa+86rUodjOQx/sRHf4C:Gr5MxzvLlfhNa6godicsd
TLSH T1BEA4794E95017199EE3C87B01078A7AC65F37FFB061A994F8E64BA6C18315C395FE20E
TrID 38.8% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
20.5% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
13.0% (.EXE) Win64 Executable (generic) (10522/11/4)
8.1% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.2% (.EXE) Win16 NE executable (generic) (5038/12/1)
Magika pebin
dhash icon 818da080a0a0a0a2 (137 x Heodo, 47 x Urelas, 30 x ValleyRAT)
Reporter aachum
Tags:2025-ip138-com CHN exe Gh0stRAT


Avatar
iamaachum
https://oogname.com/HHHSignal/ => https://www.sooxziucazdca.com/HH%E7%99%BE%E5%BA%A6/SignalSetup.zip

Gh0stRAT C2: 2025.ip138.com

Intelligence


File Origin
# of uploads :
1
# of downloads :
480
Origin country :
ES ES
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
rl_096d5e1b254aadd10aa5e86735914f4697674018b63c19a150daecdd0690f4a7
Verdict:
No threats detected
Analysis date:
2025-06-25 19:38:08 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.9%
Tags:
vmdetect emotet cobalt madi
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %AppData% directory
Creating a file
Enabling the 'hidden' option for analyzed file
Creating a process from a recently created file
Creating a process with a hidden window
Сreating synchronization primitives
DNS request
Connection attempt
Sending an HTTP GET request
Sending a custom TCP request
Searching for synchronization primitives
Launching the default Windows debugger (dwwin.exe)
Launching a process
Searching for the window
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
adaptive-context entropy krypt microsoft_visual_cc packed packed packer_detected
Result
Threat name:
n/a
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Adds extensions / path to Windows Defender exclusion list
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Contains functionality to detect sleep reduction / modifications
Contains functionality to modify windows services which are used for security filtering and protection
Creates an undocumented autostart registry key
Creates files in the system32 config directory
Creates multiple autostart registry keys
Deletes itself after installation
Disable UAC(promptonsecuredesktop)
Disable Windows Defender real time protection (registry)
Disables UAC (registry)
Found evasive API chain checking for user administrative privileges
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Reads the Security eventlog
Reads the System eventlog
Sigma detected: Execution from Suspicious Folder
Sigma detected: New RUN Key Pointing to Suspicious Folder
Sigma detected: Parent in Public Folder Suspicious Process
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Suspicious Program Location with Network Connections
Sigma detected: WScript or CScript Dropper
Uses ping.exe to check the status of other devices and networks
Uses ping.exe to sleep
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1722968 Sample: SystemProcessl77.exe Startdate: 25/06/2025 Architecture: WINDOWS Score: 100 117 ww1.purecodec.com 2->117 119 update.purecodec.com 2->119 121 3 other IPs or domains 2->121 133 Malicious sample detected (through community Yara rule) 2->133 135 Antivirus detection for dropped file 2->135 137 Antivirus / Scanner detection for submitted sample 2->137 139 9 other signatures 2->139 12 SystemProcessl77.exe 2 4 2->12         started        16 fhbmini.exe 2->16         started        18 MiniStorPlay.exe 2->18         started        20 6 other processes 2->20 signatures3 process4 file5 111 C:\Users\user\AppData\Roaming\ikiA.dcx, PE32 12->111 dropped 113 C:\$AsnDSTaTuP.KE32\Secsvl77.exe, PE32 12->113 dropped 115 C:\...\Secsvl77.exe:Zone.Identifier, ASCII 12->115 dropped 169 Found evasive API chain checking for user administrative privileges 12->169 22 Secsvl77.exe 9 65 12->22         started        27 WerFault.exe 19 16 12->27         started        171 Creates an undocumented autostart registry key 16->171 173 Creates multiple autostart registry keys 16->173 29 WallPaper.exe 16->29         started        31 fhbmini.exe 16->31         started        33 TIM.exe 18->33         started        175 Creates files in the system32 config directory 20->175 177 Reads the Security eventlog 20->177 179 Reads the System eventlog 20->179 35 WerFault.exe 2 20->35         started        37 conhost.exe 20->37         started        39 conhost.exe 20->39         started        signatures6 process7 dnsIp8 123 2025.ip138.com.wswebpic.com 140.150.29.42, 49692, 80 FUJITSU-SE-ASSE Sweden 22->123 125 38.46.11.90, 49693, 49694, 49697 COGENT-174US United States 22->125 99 C:\Users\user\AppData\Roaming\uidP.dcx, PE32 22->99 dropped 101 C:\Users\Public\Videos\_2.dll, PE32 22->101 dropped 103 C:\Users\Public\Music\_1.dll, PE32 22->103 dropped 105 32 other malicious files 22->105 dropped 143 Antivirus detection for dropped file 22->143 145 Multi AV Scanner detection for dropped file 22->145 147 Adds extensions / path to Windows Defender exclusion list 22->147 153 3 other signatures 22->153 41 Secsvl77.exe 2 22->41         started        45 powershell.exe 25 22->45         started        47 powershell.exe 1 23 22->47         started        149 Contains functionality to modify windows services which are used for security filtering and protection 29->149 151 Contains functionality to detect sleep reduction / modifications 29->151 49 WallPaper.exe 29->49         started        127 update.purecodec.com 192.157.56.140, 49710, 80 SERVER-MANIACA Canada 33->127 129 www10.smartname.com 15.197.204.56, 49711, 80 TANDEMUS United States 33->129 51 wscript.exe 33->51         started        53 MiniStorPlay.exe 35->53         started        file9 signatures10 process11 file12 107 C:\Users\user\AppData\Roaming\aulD.dcx, PE32 41->107 dropped 155 Deletes itself after installation 41->155 157 Loading BitLocker PowerShell Module 45->157 55 conhost.exe 45->55         started        57 conhost.exe 47->57         started        109 C:\Verifier\CKAxKUOI (copy), PE32 49->109 dropped 159 Adds extensions / path to Windows Defender exclusion list 49->159 59 powershell.exe 49->59         started        62 powershell.exe 49->62         started        64 WallPaper.exe 49->64         started        161 Windows Scripting host queries suspicious COM object (likely to drop second stage) 51->161 66 cmd.exe 51->66         started        69 TIM.exe 53->69         started        signatures13 process14 file15 163 Loading BitLocker PowerShell Module 59->163 71 conhost.exe 59->71         started        73 conhost.exe 62->73         started        97 C:\ProgramData\libcef.dll, PE32 66->97 dropped 165 Uses ping.exe to sleep 66->165 167 Uses ping.exe to check the status of other devices and networks 66->167 75 PING.EXE 66->75         started        78 conhost.exe 66->78         started        80 Agghosts.exe 66->80         started        84 2 other processes 66->84 82 wscript.exe 69->82         started        signatures16 process17 dnsIp18 131 127.0.0.1 unknown unknown 75->131 86 cmd.exe 82->86         started        process19 signatures20 141 Uses ping.exe to sleep 86->141 89 conhost.exe 86->89         started        91 Agghosts.exe 86->91         started        93 PING.EXE 86->93         started        95 2 other processes 86->95 process21
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PE (Portable Executable) Win 32 Exe x86
Threat name:
Win32.Malware.Heuristic
Status:
Malicious
First seen:
2025-06-19 10:31:29 UTC
AV detection:
20 of 38 (52.63%)
Threat level:
  2/5
Result
Malware family:
gh0strat
Score:
  10/10
Tags:
family:gh0strat defense_evasion discovery evasion execution persistence rat trojan upx
Behaviour
Checks processor information in registry
Modifies Control Panel
Modifies registry class
Runs ping.exe
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
System policy modification
Enumerates physical storage devices
Program crash
System Location Discovery: System Language Discovery
System Network Configuration Discovery: Internet Connection Discovery
Drops file in System32 directory
Enumerates processes with tasklist
UPX packed file
Adds Run key to start application
Checks whether UAC is enabled
Command and Scripting Interpreter: PowerShell
Enumerates connected drives
Checks computer location settings
Deletes itself
Executes dropped EXE
Loads dropped DLL
Gh0st RAT payload
Gh0strat
Gh0strat family
Modifies Windows Defender DisableAntiSpyware settings
UAC bypass
Verdict:
Suspicious
Tags:
n/a
YARA:
n/a
Unpacked files
SH256 hash:
096d5e1b254aadd10aa5e86735914f4697674018b63c19a150daecdd0690f4a7
MD5 hash:
0da96fa20bcfb5b11e3c87c468bb4f82
SHA1 hash:
0183cf76722c7e2ad6ad048c9fc649519f3ff415
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:meth_stackstrings
Author:Willi Ballenthin
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
Rule name:upx_largefile
Author:k3nr9

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gh0stRAT

Executable exe 096d5e1b254aadd10aa5e86735914f4697674018b63c19a150daecdd0690f4a7

(this sample)

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
CHECK_TRUST_INFORequires Elevated Execution (level:requireAdministrator)high
Reviews
IDCapabilitiesEvidence
WIN_BASE_APIUses Win Base APIKERNEL32.dll::LoadLibraryA
KERNEL32.dll::GetStartupInfoA

Comments