MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9cb2519a93ca905c963f7e98aab5a64e67e9c761001fa9a9c2e5fe0b95e7eed2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Zegost


Vendor detections: 15


Intelligence 15 IOCs YARA 3 File information Comments

SHA256 hash: 9cb2519a93ca905c963f7e98aab5a64e67e9c761001fa9a9c2e5fe0b95e7eed2
SHA3-384 hash: 6bd0257bcecd1ba1afc2c21a45e3a3a48b5dea17c0c565929657dbf21f44fe8037b7384a9bfb4ff79256cfcf3753d4d2
SHA1 hash: ba67822cdddde74685e6a8d8026ef40486ed3b84
MD5 hash: bd3f6cab6425924732ab68965574084b
humanhash: kentucky-red-earth-nineteen
File name:ExeFile (297).exe
Download: download sample
Signature Zegost
File size:55'296 bytes
First seen:2024-08-20 14:12:14 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 8999f02b716fe8349a4fb9d0afb520ab (1 x Zegost)
ssdeep 1536:ypv9bPvTMu9qdzJBYujh3EEGsZj8Mk+nouy8Q:0vJ3r9kTx3u0outQ
Threatray 22 similar samples on MalwareBazaar
TLSH T1B643F161DA98C28FC9AA95F054934B2A083AA304C356DB7A5F30306F6DE9E507F5C773
TrID 39.9% (.EXE) UPX compressed Win32 Executable (27066/9/6)
24.3% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
9.7% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
7.4% (.EXE) Win16 NE executable (generic) (5038/12/1)
6.6% (.EXE) Win32 Executable (generic) (4504/4/1)
Reporter byMattii1234
Tags:Zegost

Intelligence


File Origin
# of uploads :
1
# of downloads :
88
Origin country :
DE DE
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
ExeFile (297).exe
Verdict:
Malicious activity
Analysis date:
2024-08-20 15:03:01 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.1%
Tags:
Static Stealth Trojan Farfli Pcclient
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
farfli hook installer microsoft_visual_cc packed packed packed razy upx
Result
Threat name:
GhostRat
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
AI detected suspicious sample
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
C2 URLs / IPs found in malware configuration
Contains functionality to detect sleep reduction / modifications
Deletes itself after installation
Found malware configuration
Machine Learning detection for dropped file
Machine Learning detection for sample
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Yara detected GhostRat
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1495985 Sample: ExeFile (297).exe Startdate: 20/08/2024 Architecture: WINDOWS Score: 100 21 sky.hobuff.info 2->21 25 Found malware configuration 2->25 27 Antivirus detection for dropped file 2->27 29 Antivirus / Scanner detection for submitted sample 2->29 31 8 other signatures 2->31 6 svchost.exe 2->6         started        10 ExeFile (297).exe 2 7 2->10         started        13 svchost.exe 41 2->13         started        15 svchost.exe 2->15         started        signatures3 process4 dnsIp5 23 sky.hobuff.info 127.0.0.1 unknown unknown 6->23 33 Deletes itself after installation 6->33 17 C:\Program Files (x86)\conhost.psd, PE32 10->17 dropped 19 C:\2514400.dll, PE32 10->19 dropped file6 signatures7
Threat name:
Win32.Backdoor.Farfli
Status:
Malicious
First seen:
2019-01-02 23:16:56 UTC
File Type:
PE (Exe)
Extracted files:
14
AV detection:
35 of 38 (92.11%)
Threat level:
  5/5
Result
Malware family:
gh0strat
Score:
  10/10
Tags:
family:gh0strat discovery rat upx
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: LoadsDriver
Suspicious use of AdjustPrivilegeToken
System Location Discovery: System Language Discovery
Drops file in Program Files directory
Deletes itself
Loads dropped DLL
UPX packed file
Gh0st RAT payload
Gh0strat
Verdict:
Suspicious
Tags:
n/a
YARA:
n/a
Unpacked files
SH256 hash:
437db04d31060f858ec6931e7a0e50f7b932e6e24763e1ffcaa3f34b4cba188e
MD5 hash:
3ced50db27663f74cc38df60ef0a43cc
SHA1 hash:
183723b2fc5d0160368031f412fc13b96e553e2d
SH256 hash:
3f7c36f42f175863bbb37c895dbabeb3dae8e9bf4bd49d4e13d46b4074ca3be4
MD5 hash:
98874367db26bf9e8c486a910907b80e
SHA1 hash:
b6bb1b7bdc01ea9efa927d70f307709fe546bd6d
SH256 hash:
9cb2519a93ca905c963f7e98aab5a64e67e9c761001fa9a9c2e5fe0b95e7eed2
MD5 hash:
bd3f6cab6425924732ab68965574084b
SHA1 hash:
ba67822cdddde74685e6a8d8026ef40486ed3b84
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:UPX20030XMarkusOberhumerLaszloMolnarJohnReiser
Author:malware-lu
Rule name:UPXV200V290MarkusOberhumerLaszloMolnarJohnReiser
Author:malware-lu
Rule name:UPXv20MarkusLaszloReiser
Author:malware-lu

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Zegost

Executable exe 9cb2519a93ca905c963f7e98aab5a64e67e9c761001fa9a9c2e5fe0b95e7eed2

(this sample)

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
WIN_BASE_APIUses Win Base APIKERNEL32.DLL::LoadLibraryA
WIN_REG_APICan Manipulate Windows RegistryADVAPI32.dll::RegOpenKeyA

Comments