🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7d4ac96fdb795ce62387ec368fb58c2e71956d2265dbbcc6bc1360e254235fb8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gh0stRAT


Vendor detections: 15


Intelligence 15 IOCs 1 YARA 9 File information Comments

SHA256 hash: 7d4ac96fdb795ce62387ec368fb58c2e71956d2265dbbcc6bc1360e254235fb8
SHA3-384 hash: 20b720af9bcf26982e7bb6fcbae55c106b2656aa81cb55bf0507d913b61766191b3df72b425bb65b4216545ea30996eb
SHA1 hash: 42031bac12e4317846fa3bec03cab2e6feb8f016
MD5 hash: 8c6f2f0bc2347180b475ca00bcb6ac52
humanhash: michigan-undress-kansas-rugby
File name:8c6f2f0bc2347180b475ca00bcb6ac52.exe
Download: download sample
Signature Gh0stRAT
File size:174'080 bytes
First seen:2025-07-01 08:05:12 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash cac04ac6b8017de2c4ca440c6cdd17dc (1 x Gh0stRAT)
ssdeep 3072:DR8qdMMDI78WG9pg66zAF9l02vtIY1+mKd1MQ9hC6VHMjaXv88b8vAD4:DR8qGMDIwWgL6zAF97/0dz9hTVHMjaNs
TLSH T12F04D011E6A1D02ADCD361F687A7DB6DF6266E3B030510CFA3A4695B132E1E0BC31D76
TrID 40.3% (.EXE) Win64 Executable (generic) (10522/11/4)
19.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
17.2% (.EXE) Win32 Executable (generic) (4504/4/1)
7.7% (.EXE) OS/2 Executable (generic) (2029/13)
7.6% (.EXE) Generic Win/DOS Executable (2002/3)
Magika pebin
dhash icon c9d4c4cda6a8cec6 (5 x Gh0stRAT, 2 x FatalRAT, 2 x Formbook)
Reporter abuse_ch
Tags:exe Gh0stRAT RAT


Avatar
abuse_ch
Gh0stRAT C2:
185.107.56.195:443

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
185.107.56.195:443 https://threatfox.abuse.ch/ioc/1551892/

Intelligence


File Origin
# of uploads :
1
# of downloads :
135
Origin country :
NL NL
Vendor Threat Intelligence
Malware family:
ID:
1
File name:
rl_7d4ac96fdb795ce62387ec368fb58c2e71956d2265dbbcc6bc1360e254235fb8
Verdict:
Malicious activity
Analysis date:
2025-07-01 08:20:22 UTC
Tags:
auto-reg remote rat gh0st

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
96.5%
Tags:
farfli madi
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% directory
Creating a process from a recently created file
Creating a process with a hidden window
Сreating synchronization primitives
Running batch commands
Launching a process
Searching for synchronization primitives
Launching the default Windows debugger (dwwin.exe)
Connection attempt to an infection source
Sending a TCP request to an infection source
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Query of malicious DNS domain
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug base64 cmd evasive farfli gh0strat lolbin microsoft_visual_cc moudoor packed packed
Result
Threat name:
GhostRat
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Contains functionality to access PhysicalDrive, possible boot sector overwrite
Contains functionality to capture and log keystrokes
Contains functionality to detect sleep reduction / modifications
Contains functionality to infect the boot sector
Found evasive API chain (may stop execution after checking mutex)
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Self deletion via cmd or bat file
Sigma detected: New RUN Key Pointing to Suspicious Folder
Submitted sample is a known malware sample
Suricata IDS alerts for network traffic
Tries to delay execution (extensive OutputDebugStringW loop)
Uses ping.exe to check the status of other devices and networks
Uses ping.exe to sleep
Yara detected GhostRat
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1726198 Sample: ESKK8211qC.exe Startdate: 01/07/2025 Architecture: WINDOWS Score: 100 37 icybin.flnet.org 2->37 51 Suricata IDS alerts for network traffic 2->51 53 Malicious sample detected (through community Yara rule) 2->53 55 Antivirus detection for dropped file 2->55 57 5 other signatures 2->57 8 ESKK8211qC.exe 1 2 2->8         started        12 vptray.exe 2->12         started        14 vptray.exe 2->14         started        signatures3 process4 file5 31 C:\Users\user\AppData\Local\Temp\vptray.exe, PE32 8->31 dropped 33 C:\Users\user\...\vptray.exe:Zone.Identifier, ASCII 8->33 dropped 59 Self deletion via cmd or bat file 8->59 16 vptray.exe 2 8->16         started        21 cmd.exe 1 8->21         started        signatures6 process7 dnsIp8 35 icybin.flnet.org 185.107.56.53, 443, 49715, 49722 NFORCENL Netherlands 16->35 29 C:\Users\user\AppData\Local\Temp\up.bak, PE32 16->29 dropped 39 Antivirus detection for dropped file 16->39 41 Multi AV Scanner detection for dropped file 16->41 43 Submitted sample is a known malware sample 16->43 49 6 other signatures 16->49 23 WerFault.exe 19 16 16->23         started        45 Uses ping.exe to sleep 21->45 47 Uses ping.exe to check the status of other devices and networks 21->47 25 conhost.exe 21->25         started        27 PING.EXE 1 21->27         started        file9 signatures10 process11
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PE (Portable Executable) Win 32 Exe x86
Threat name:
Win32.Backdoor.Moudoor
Status:
Malicious
First seen:
2025-06-27 19:57:00 UTC
File Type:
PE (Exe)
Extracted files:
2
AV detection:
35 of 38 (92.11%)
Threat level:
  5/5
Result
Malware family:
gh0strat
Score:
  10/10
Tags:
family:gh0strat discovery persistence rat
Behaviour
Checks processor information in registry
Runs ping.exe
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of WriteProcessMemory
Program crash
System Location Discovery: System Language Discovery
System Network Configuration Discovery: Internet Connection Discovery
Adds Run key to start application
Executes dropped EXE
Loads dropped DLL
Gh0st RAT payload
Gh0strat
Gh0strat family
Unpacked files
SH256 hash:
7d4ac96fdb795ce62387ec368fb58c2e71956d2265dbbcc6bc1360e254235fb8
MD5 hash:
8c6f2f0bc2347180b475ca00bcb6ac52
SHA1 hash:
42031bac12e4317846fa3bec03cab2e6feb8f016
SH256 hash:
05b144506d9a8f0ce509750312d0fef777dfb0e7eb7cdc48c20772829c0198db
MD5 hash:
0ddb181ea4117b45671eb0f6ced306cc
SHA1 hash:
39658cc636ab439facac2b71c4dd0fabea8f9141
SH256 hash:
305ada6fc25da454c35daffe3f02a8a5b3be68939c9798b0705b1d66ca4fda1a
MD5 hash:
e5875af59feed7b0af8997783e990d1f
SHA1 hash:
48e3178f03e800647b6e1cb900119a0b6ccdb5c5
SH256 hash:
096417751976e97ae250b6b290b30ea0d429ee2cb012acde6823c6cf2e0d41f5
MD5 hash:
0c186f5a42901c3deff0d9d62a065564
SHA1 hash:
7c939c8cd3c65167bec84095d65248d39d102da6
Detections:
GhostDragon_Gh0stRAT SUSP_XORed_MSDOS_Stub_Message INDICATOR_SUSPICIOUS_EXE_RegKeyComb_RDP
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Armadillov1xxv2xx
Author:malware-lu
Rule name:Check_OutputDebugStringA_iat
Rule name:CMD_Ping_Localhost
Rule name:GhostDragon_Gh0stRAT
Author:Florian Roth (Nextron Systems)
Description:Detects Gh0st RAT mentioned in Cylance' Ghost Dragon Report
Reference:https://blog.cylance.com/the-ghost-dragon
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:INDICATOR_SUSPICIOUS_EXE_RegKeyComb_RDP
Author:ditekSHen
Description:Detects executables embedding registry key / value combination manipulating RDP / Terminal Services
Rule name:InstallShield2000
Author:malware-lu
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CloseHandle
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::LoadLibraryA
KERNEL32.dll::GetStartupInfoA
KERNEL32.dll::GetCommandLineA
WIN_BASE_EXEC_APICan Execute other programsKERNEL32.dll::SetStdHandle
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CopyFileA
KERNEL32.dll::GetTempPathA
WIN_REG_APICan Manipulate Windows RegistryADVAPI32.dll::RegCreateKeyA
ADVAPI32.dll::RegCreateKeyExA
ADVAPI32.dll::RegDeleteKeyA
ADVAPI32.dll::RegSetValueExA

Comments