🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a95a25d7fe1d46df94f992e3a56be45edf5ef8f013aea95585a3b2f2d3bf9993. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gh0stRAT


Vendor detections: 17


Intelligence 17 IOCs 1 YARA 18 File information Comments

SHA256 hash: a95a25d7fe1d46df94f992e3a56be45edf5ef8f013aea95585a3b2f2d3bf9993
SHA3-384 hash: 4e87324f3ada63d5e4371fabb278e297eb65925768c7de20eb0153dcc813367743c5564ca23279e5dbcecb1e7524cbbe
SHA1 hash: ef9c9a2719cb4c7071ca2eab6350c2f16f8e9a2b
MD5 hash: f46964c916274c48513d8f3cd0ad289d
humanhash: lithium-item-six-ack
File name:F46964C916274C48513D8F3CD0AD289D.exe
Download: download sample
Signature Gh0stRAT
File size:5'193'728 bytes
First seen:2025-11-25 07:05:09 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 2cb0f92664b0129f2adcd077ab089016 (1 x Gh0stRAT)
ssdeep 98304:4kkw8mJ0LMyfwX239FEBCh8pJisPgQuR7F/8cxsPB8E+QsPddJsPhOKsP:+ZpROC4q/JEze
Threatray 67 similar samples on MalwareBazaar
TLSH T19736BF01B781C032EAAB017099BDEB7A557DFA300B2585C7A3C42F5D6E305D2AE3975B
TrID 37.8% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
20.0% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
12.7% (.EXE) Win64 Executable (generic) (10522/11/4)
7.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
Magika pebin
dhash icon f8fcee8e8e88e060 (1 x CobaltStrike, 1 x Gh0stRAT)
Reporter abuse_ch
Tags:exe Gh0stRAT RAT


Avatar
abuse_ch
Gh0stRAT C2:
101.43.156.141:6000

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
101.43.156.141:6000 https://threatfox.abuse.ch/ioc/1649892/

Intelligence


File Origin
# of uploads :
1
# of downloads :
166
Origin country :
NL NL
Vendor Threat Intelligence
Malware family:
ID:
1
File name:
F46964C916274C48513D8F3CD0AD289D.exe
Verdict:
Malicious activity
Analysis date:
2025-11-25 07:07:32 UTC
Tags:
payload remote rat gh0st auto-reg

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.9%
Tags:
shellcode dropper emotet virus
Result
Verdict:
Malware
Maliciousness:

Behaviour
Connection attempt
Sending an HTTP GET request
Launching cmd.exe command interpreter
Сreating synchronization primitives
Creating a window
Creating a file
Searching for the window
Sending a custom TCP request
DNS request
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Unauthorized injection to a system process
Verdict:
Malicious
File Type:
exe x32
First seen:
2025-11-22T11:06:00Z UTC
Last seen:
2025-11-26T08:19:00Z UTC
Hits:
~100
Detections:
HEUR:Trojan-Spy.Win32.AntiAV.gen Backdoor.Win32.Androm PDM:Trojan.Win32.Generic Backdoor.Agent.TCP.C&C Trojan-Dropper.Win32.Injector.sb Trojan-Dropper.Win32.Dapato.sb Trojan.Win32.Inject.sb Trojan.Win32.Agent.sb Backdoor.Win32.WOC.sb
Result
Threat name:
GhostRat
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Allocates memory in foreign processes
C2 URLs / IPs found in malware configuration
Contain functionality to detect virtual machines
Contains functionality to access PhysicalDrive, possible boot sector overwrite
Contains functionality to infect the boot sector
Contains functionality to inject code into remote processes
Found API chain indicative of debugger detection
Found API chain indicative of sandbox detection
Found malware configuration
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Multi AV Scanner detection for submitted file
Sigma detected: Potentially Suspicious Malware Callback Communication
Uses known network protocols on non-standard ports
Writes to foreign memory regions
Yara detected GhostRat
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1820358 Sample: sm1Yt7Ft8a.exe Startdate: 25/11/2025 Architecture: WINDOWS Score: 100 32 iamasbcx.asuscomm.com 2->32 44 Found malware configuration 2->44 46 Multi AV Scanner detection for submitted file 2->46 48 Yara detected GhostRat 2->48 50 4 other signatures 2->50 8 sm1Yt7Ft8a.exe 1 13 2->8         started        13 sm1Yt7Ft8a.exe 12 2->13         started        15 sm1Yt7Ft8a.exe 12 2->15         started        signatures3 process4 dnsIp5 34 101.43.156.141, 49687, 49688, 49695 CNIX-APChinaNetworksInter-ExchangeCN China 8->34 30 C:\Users\user\AppData\Local\...\1[1].bin, DOS 8->30 dropped 52 Contains functionality to inject code into remote processes 8->52 54 Writes to foreign memory regions 8->54 56 Allocates memory in foreign processes 8->56 17 cmd.exe 9 1 8->17         started        58 Injects a PE file into a foreign processes 13->58 20 cmd.exe 13->20         started        22 cmd.exe 15->22         started        file6 signatures7 process8 signatures9 36 Contains functionality to access PhysicalDrive, possible boot sector overwrite 17->36 38 Found API chain indicative of debugger detection 17->38 40 Found API chain indicative of sandbox detection 17->40 42 2 other signatures 17->42 24 WerFault.exe 20 16 17->24         started        26 WerFault.exe 21 20->26         started        28 WerFault.exe 21 22->28         started        process10
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout Win 32 Exe x86
Result
Malware family:
n/a
Score:
  6/10
Tags:
discovery persistence
Behaviour
System Location Discovery: System Language Discovery
Adds Run key to start application
Unpacked files
SH256 hash:
a95a25d7fe1d46df94f992e3a56be45edf5ef8f013aea95585a3b2f2d3bf9993
MD5 hash:
f46964c916274c48513d8f3cd0ad289d
SHA1 hash:
ef9c9a2719cb4c7071ca2eab6350c2f16f8e9a2b
SH256 hash:
28efc67df575ad40fc71ec6f8dbe12317e1928a4c1dc4b57f3a6dfda34149ede
MD5 hash:
c962b36128fbba1ed24ffffb9fb014f0
SHA1 hash:
d103f24f296b410306d43cab4c8183f942165617
SH256 hash:
f5e826458c79845a3b017fc34b0c03d8a6f4b3d2bb58685386a9e87c76842768
MD5 hash:
a7bcb312c4b33a9f639099a8540e647c
SHA1 hash:
4383bf470b167b7619c4f6048b3799b92ca0bc00
Detections:
win_samsam_auto
SH256 hash:
b4f8d05e85a7965cbe65a0c33208c0bcaf9a72baedadf6af713352b549620a62
MD5 hash:
1e974833b874430f12b796ebc175237a
SHA1 hash:
b42f91ed7a665e6162defd4d81062c633b9bc679
SH256 hash:
b9ca4fa6df8cd07278b8d3fd5d6fa3fff516884f75038ebdfc5d648d570b436b
MD5 hash:
4db3e4424af850864a2d9199ca6d7092
SHA1 hash:
893e38423e90e1d8ac86a8755f5d22ab9edb2436
SH256 hash:
528cd2f7944bd512c44f3874d823caf86ad9dddf1ac37c4e8cd47310b8fed6c6
MD5 hash:
55e8405ca1a140ae6dfd60e990ce3def
SHA1 hash:
4c02283af0f49d243c3dea01066d07a932cd1198
Detections:
win_samsam_auto
SH256 hash:
b5745506409bdf3969e85e87982a8d610986dfe0158ed581edaeb1a702c9e817
MD5 hash:
baaef314eb1dc199d10fe47803da9d36
SHA1 hash:
2c7ad3368bad9633394d1aa66e3f3ccbf035f76b
SH256 hash:
ba0eab2608f8f98b31b8aa305b1b00508abcd3371c297b20772a98da0d7b20f4
MD5 hash:
b2c6c584989d72590936d363597a6bb1
SHA1 hash:
a18677f9a4c5efd810ac7de837d96c1b2d313b68
SH256 hash:
7b6c8e2418446b18bad4c04e8e1e956b981f651e7b552bd885f5d5849fc55fcb
MD5 hash:
01e9e8696c27736377fd3c8f94c2aef1
SHA1 hash:
3d92aa30ed33ae742a9f620fc4d5b38bc48d624e
Malware family:
ValleyRAT
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Check_DriveSize
Rule name:cleanup_loader_payload_v1
Author:RandomMalware
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:dgaagas
Author:Harshit
Description:Uses certutil.exe to download a file named test.txt
Rule name:Gh0stKCP
Author:Netresec
Description:Detects HP-Socket ARQ and KCP implementations, which are used in Gh0stKCP. Forked from @stvemillertime's KCP catchall rule.
Reference:https://netresec.com/?b=259a5af
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques
Rule name:Windows_Trojan_DustyWarehouse_a6cfc9f7
Author:Elastic Security

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments