MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7e4420e487e1398f3b554fc20c069433df24c3883caae35125be1802e25849b3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gh0stRAT


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 7e4420e487e1398f3b554fc20c069433df24c3883caae35125be1802e25849b3
SHA3-384 hash: b11175eef369d11bc2bc34f2af4517ea828a7dbba79e637f19696c0bf2d713db98fddef2e5e18ddde62b3666786e4170
SHA1 hash: 2b14a58ebcf538a39998d1066ec20b3ba88cfdbb
MD5 hash: 9a6f3e4b4f8ead2ab0a2532ad500fdb5
humanhash: cup-foxtrot-mountain-september
File name:Terrorist activities in Cambodia 07.29.2026.7z
Download: download sample
Signature Gh0stRAT
File size:19'571'813 bytes
First seen:2026-07-30 13:25:44 UTC
Last seen:Never
File type: 7z
MIME type:application/x-7z-compressed
ssdeep 393216:uT6LNC27yIM95niKgT+H4+T2dQkVt0uOtTJ1sj9ElPQpPCO:uT6ZD7K95no6Yo0QkVtnIJQ9APQPCO
TLSH T13C173380DAEECBB573C248FA32633D92C8D47E241B3DE5B57642D593429EB5AC5243B0
TrID 57.1% (.7Z) 7-Zip compressed archive (v0.4) (8000/1)
42.8% (.7Z) 7-Zip compressed archive (gen) (6000/1)
Magika sevenzip
Reporter smica83
Tags:7z Gh0stRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
76
Origin country :
HU HU
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Terrorist activities in Cambodia 07.29.2026.exe
File size:21'803'416 bytes
SHA256 hash: 7958a2b378ae08a2f018365d43614fd38ef51863ca46841ebb9670e71510ba0e
MD5 hash: 87d416f944514d90dd1232d9de44268e
MIME type:application/x-dosexec
Signature Gh0stRAT
Vendor Threat Intelligence
No detections
Result
Verdict:
Malicious
File Type:
PE File
Behaviour
BlacklistAPI detected
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
adaptive-context anti-debug embarcadero_delphi evasive explorer fingerprint inno installer installer installer-heuristic keylogger lolbin overlay packed packed reconnaissance rundll32 runonce
Verdict:
Malicious
File Type:
7z
First seen:
2026-07-30T11:40:00Z UTC
Last seen:
2026-07-30T11:55:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
.Net 7z Archive Executable PE (Portable Executable) PE File Layout SFX 7z
Threat name:
Win32.Backdoor.Farfli
Status:
Suspicious
First seen:
2026-07-30 00:09:13 UTC
File Type:
Binary (Archive)
Extracted files:
29
AV detection:
14 of 37 (37.84%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
command_and_control discovery
Behaviour
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
System Location Discovery: System Language Discovery
Executes dropped EXE
Loads dropped DLL
Outbound SSH connection to public host
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments