MALICIOUS — 0db86074ffe79db8018fce56819b50748ea822defb132377248c51343e2ec903
MALICIOUS — 0db86074ffe79db8018fce56819b50748ea822defb132377248c51343e2ec903 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (93/100), attributed to the Gh0stRAT family. 7 of 55 detection engines flagged it.
Identification
- SHA-256:
0db86074ffe79db8018fce56819b50748ea822defb132377248c51343e2ec903 - SHA-1:
035d4db3119146e2fd4d6dd8782b85f787f4ddc9 - MD5:
3481d8c08833cd6e035e7f57dbc52958 - imphash:
e58ab46f2a279ded0846d81bf0fa21f7 - ssdeep:
1536:2fpTjzqsfAJNXr0Q+UPkM604fW2RU2ZjC+No/:2BfcNb0Qp8MbEU2Zjvq/ - TLSH:
T1AA35F169152A9C88D1F1DD286CF32CDE50B20832B7BB7D555872B1CB17082E3ABC571A - Submitted as: 0db86074ffe79db8018fce56819b50748ea822defb132377248c51343e2ec903
- File type: pe · Size: 59904 bytes
- Verdict: malicious (93/100) · Family: Gh0stRAT
Detections (7 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Dropper.Gh0stRAT-9856256-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Microsoft Defender: Trojan:Win32/Antavmu.GFS!MTB
- Emsisoft (Emergency Kit): Gen:Variant.Farfli.64
- Kaspersky (KVRT): VHO:Backdoor.Win32.Farfli.gen
Why this verdict
The malicious score of 93/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Dropper.Gh0stRAT-9856256-0 (rule
Win.Dropper.Gh0stRAT-9856256-0) - engine signal, weight 0.90, confidence 0.95 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: UPX, high-entropy-sections:UPX1, Microsoft Linker - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded domains
- xy9.com
More Gh0stRAT samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report