MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a3b7929d37805fa49dda5200049f664f38c6832fcc8d9d58f4afb7d7906a2d23. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gh0stRAT


Vendor detections: 11


Intelligence 11 IOCs 1 YARA File information Comments

SHA256 hash: a3b7929d37805fa49dda5200049f664f38c6832fcc8d9d58f4afb7d7906a2d23
SHA3-384 hash: f7c0f8f55b29141cb7ded753fbf915c065dac5738e655d0669b757937e64b8a04a7798180d21d09e493af5e1dc295e1f
SHA1 hash: e66c74d7e7dfbf6ad67678a9948ab08f59469604
MD5 hash: e821590c03872a304c25315ab46005a3
humanhash: grey-oregon-summer-south
File name:e821590c03872a304c25315ab46005a3.exe
Download: download sample
Signature Gh0stRAT
File size:64'528 bytes
First seen:2022-02-23 14:37:23 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash b2ab9c868a88adb1bc668cb8d724d018 (1 x Gh0stRAT)
ssdeep 1536:QOP1q+mQ29I4uBbHOZ0km257VnGJDZc8FZtjQBl/CCcizMo:QvDAXkmS7RGJDZc6al9eo
Threatray 7 similar samples on MalwareBazaar
TLSH T11D53F16481D1655BD5E208F0289F87606910EF1B358C5A0FE6A97D2C7CAF38F4BB3366
File icon (PE):PE icon
dhash icon 30b6c6cec4e8cea0 (1 x Gh0stRAT)
Reporter abuse_ch
Tags:exe Gh0stRAT


Avatar
abuse_ch
Gh0stRAT C2:
118.184.169.48:80

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
118.184.169.48:80 https://threatfox.abuse.ch/ioc/390318/

Intelligence


File Origin
# of uploads :
1
# of downloads :
211
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
one_smol_rat_boi.exe
Verdict:
Malicious activity
Analysis date:
2022-02-23 17:28:25 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file
Launching a service
Creating a file in the Windows subdirectories
Loading a system driver
Сreating synchronization primitives
Creating a service
Creating a file in the Windows directory
DNS request
Enabling autorun for a service
Result
Malware family:
n/a
Score:
  5/10
Tags:
n/a
Behaviour
MalwareBazaar
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
overlay packed
Result
Threat name:
GhostRat
Detection:
malicious
Classification:
troj
Score:
80 / 100
Signature
Antivirus / Scanner detection for submitted sample
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
PE file has a writeable .text section
Yara detected GhostRat
Behaviour
Behavior Graph:
Threat name:
Win32.Infostealer.Magania
Status:
Malicious
First seen:
2011-05-26 11:35:00 UTC
File Type:
PE (Exe)
Extracted files:
3
AV detection:
38 of 43 (88.37%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
suricata
Behaviour
Checks processor information in registry
Modifies data under HKEY_USERS
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: LoadsDriver
Suspicious use of AdjustPrivilegeToken
Drops file in Windows directory
Deletes itself
Loads dropped DLL
suricata: ET MALWARE Backdoor family PCRat/Gh0st CnC traffic
suricata: ET MALWARE Backdoor family PCRat/Gh0st CnC traffic (OUTBOUND) 102
suricata: ET MALWARE Gh0st Remote Access Trojan Encrypted Session To CnC Server
Unpacked files
SH256 hash:
a3b7929d37805fa49dda5200049f664f38c6832fcc8d9d58f4afb7d7906a2d23
MD5 hash:
e821590c03872a304c25315ab46005a3
SHA1 hash:
e66c74d7e7dfbf6ad67678a9948ab08f59469604
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments