MALICIOUS — 1de862ad0ecdc1785f4706e3ae7caaa65b781cbf7ac572f2b1b7f5becd1ad3fc
MALICIOUS — 1de862ad0ecdc1785f4706e3ae7caaa65b781cbf7ac572f2b1b7f5becd1ad3fc is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (93/100), attributed to the Gh0stRAT family. 5 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1de862ad0ecdc1785f4706e3ae7caaa65b781cbf7ac572f2b1b7f5becd1ad3fc - SHA-1:
332b4de3efcb3eaec5e0a5d717eb81253b80aa56 - MD5:
9a2dd1a4471f11dddf96622cbae9a91f - imphash:
385c283706f3acb2b88badd4d0ed4451 - ssdeep:
768:FQFqhgEyJc0+oD7DGPMRfWTYJVNf5mCnJcB:u4hIJ64fWENf442B - TLSH:
T1E8353A9AF36AFB5AF5728FF3D4012C1C6169A4FD60E21C882903D45B0D60C9364AB17E - Submitted as: 1de862ad0ecdc1785f4706e3ae7caaa65b781cbf7ac572f2b1b7f5becd1ad3fc
- File type: pe · Size: 61440 bytes
- Verdict: malicious (93/100) · Family: Gh0stRAT
Detections (5 of 52 engines)
- ClamAV (daily): Win.Trojan.Gh0stRAT-7480037-0
- YARA: Stratosphere IPS: STRATO_Malicious_UserAgent
- Microsoft Defender: Trojan:Win32/Pynamer.A!rfn
- Emsisoft (Emergency Kit): Dropped:Generic.Malware.F!dld!.0DDE1ECF
- Kaspersky (KVRT): UDS:Trojan.Win32.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 93/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Gh0stRAT-7480037-0 (rule
Win.Trojan.Gh0stRAT-7480037-0) - engine signal, weight 0.90, confidence 0.95 - YARA: Stratosphere IPS flagged STRATO_Malicious_UserAgent (rule
STRATO_Malicious_UserAgent) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: 103.230.240.93 - static signal, weight 0.35, confidence 0.60
- communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded IP addresses
- 103.230.240.93
- 192.168.1.32
- 192.168.1.244
More Gh0stRAT samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report