MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3f5cb4f42afb4b77f5734d143e352b134f5825f4022eaeb5bdaf4b6e243d8fc3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gh0stRAT


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 3f5cb4f42afb4b77f5734d143e352b134f5825f4022eaeb5bdaf4b6e243d8fc3
SHA3-384 hash: 0ba2a1e071d5ca57a5c5ec046e09e98f6f33ee77e8336563480cb9ffee7c7f31946a6f46509825bfb2cf9e229c317671
SHA1 hash: 717d7af8880bbbc6fcf30978ec3286da221fa9aa
MD5 hash: 5a9aafcc93026897a90d61d6eb417f0a
humanhash: solar-vermont-washington-illinois
File name:2026 Event Promotion – Discounted Prices.rar
Download: download sample
Signature Gh0stRAT
File size:19'455'283 bytes
First seen:2026-07-30 13:28:42 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 393216:skILtnRfDl7qK+LRjEfLWHNcjtpC+FP3IexsDSESM1x1X15vuvC:KLtRfpd+2fYS3S2WSESKX15vuK
TLSH T15C1733E72CC29520CAA78A76C75A8E3470C09B9C06E9E774F837A0DED88D73391467D5
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Magika rar
Reporter smica83
Tags:Gh0stRAT rar

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
HU HU
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:2026 Event Promotion – Discounted Prices.exe
File size:19'978'467 bytes
SHA256 hash: a1d8fdb2599eab487442443b5264d179bee24299991de1f30e6a99edc3b56f7d
MD5 hash: eb9672c3d3e108900a92352e5a831c6c
MIME type:application/x-dosexec
Signature Gh0stRAT
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context adaptive-context anti-debug embarcadero_delphi evasive fingerprint inno installer installer installer-heuristic lolbin overlay packed packed reconnaissance rundll32 runonce
Verdict:
Malicious
File Type:
rar
First seen:
2026-07-30T04:56:00Z UTC
Last seen:
2026-08-01T09:35:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
1 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Rar Archive
Threat name:
Win32.Trojan.Ravartar
Status:
Malicious
First seen:
2026-07-29 23:38:17 UTC
File Type:
Binary (Archive)
Extracted files:
15
AV detection:
20 of 37 (54.05%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery installer
Behaviour
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Inno Setup is an open-source installation builder for Windows applications.
System Location Discovery: System Language Discovery
Executes dropped EXE
Loads dropped DLL
Unexpected DNS network traffic destination
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments