MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0b10761472959c21047f3e82f9c59f0e988c30b8501cdb4818539805eeafbf65. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gh0stRAT


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 0b10761472959c21047f3e82f9c59f0e988c30b8501cdb4818539805eeafbf65
SHA3-384 hash: 6aecab4e475aba76e19e28b56b589065a4fa5ed512510ac263d457cdce53a99cb1787bf275c9233efe28c0a2d7dc5446
SHA1 hash: 0ad2d282e23bf94f34b8d013a1d34cd7cf18151f
MD5 hash: 4b3b2b46bb88e6c616a1e05971491957
humanhash: cat-jig-fifteen-fourteen
File name:GAPI32.dll
Download: download sample
Signature Gh0stRAT
File size:1'000'960 bytes
First seen:2022-05-30 11:01:25 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 640097f08d773aeaa4b61060db7ac139 (1 x Gh0stRAT)
ssdeep 24576:vj0qQ7NHN3+zEnnG2EiBGE7U3lYhJwAl66:vAqpzkBU3luJwAl66
Threatray 14 similar samples on MalwareBazaar
TLSH T1D8252929E70715F4E61393B1865EEB7BA718B9188022AF7FFF4BCA94B4331123D49152
TrID 44.6% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
23.6% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
9.4% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
7.2% (.EXE) Win16 NE executable (generic) (5038/12/1)
6.4% (.EXE) Win32 Executable (generic) (4505/5/1)
Reporter obfusor
Tags:dll Gh0stRAT GhostRat

Intelligence


File Origin
# of uploads :
1
# of downloads :
257
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Sending a custom TCP request
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
52 / 100
Signature
Creates an autostart registry key pointing to binary in C:\Windows
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 636132 Sample: GAPI32.dll Startdate: 30/05/2022 Architecture: WINDOWS Score: 52 24 Multi AV Scanner detection for submitted file 2->24 7 loaddll32.exe 1 2->7         started        9 rundll32.exe 2->9         started        11 rundll32.exe 2->11         started        process3 process4 13 rundll32.exe 1 7->13         started        16 cmd.exe 1 7->16         started        18 rundll32.exe 7->18         started        20 6 other processes 7->20 signatures5 26 Creates an autostart registry key pointing to binary in C:\Windows 13->26 22 rundll32.exe 16->22         started        process6
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2022-05-30 11:10:19 UTC
AV detection:
10 of 26 (38.46%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
persistence
Behaviour
Suspicious use of WriteProcessMemory
Adds Run key to start application
Unpacked files
SH256 hash:
0b10761472959c21047f3e82f9c59f0e988c30b8501cdb4818539805eeafbf65
MD5 hash:
4b3b2b46bb88e6c616a1e05971491957
SHA1 hash:
0ad2d282e23bf94f34b8d013a1d34cd7cf18151f
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments