Trend graph by period


Related keyword cloud
Top 100

# Trend Count Comparison
1GhostRAT 1 - 0 (0%)
2low 1 ▲ new
3Uploaded 1 ▲ new
4abusech 1 ▲ new
5httpstcowU 1 ▲ new
6NetWireRC 1 - 0 (0%)
Special keyword group
Top 5

Malware Type
Malware Type

This is the type of malware that is becoming an issue.


Keyword Average Label
NetWireRC
1 (100%)
Attacker & Actors
Attacker & Actors

The status of the attacker or attack group being issued.


No data.

Attack technique
Technique

This is an attack technique that is becoming an issue.


No data.

Country & Company
Country & Company

This is a country or company that is an issue.


No data.

Threat info
Last 5

Additional information

Level Description
danger File has been identified by 68 AntiVirus engines on VirusTotal as malicious
watch Communicates with host for which no DNS query was performed
watch Creates known Zegost files
watch Detects VMWare through the in instruction feature
watch Installs itself for autorun at Windows startup
notice A process attempted to delay the analysis task.
notice Allocates read-write-execute memory (usually to unpack itself)
notice Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time)
notice Expresses interest in specific running processes
notice Foreign language identified in PE resource
notice Searches running processes potentially to identify processes for sandbox evasion
notice The binary likely contains encrypted or compressed data indicative of a packer
info One or more processes crashed
info The executable uses a known packer
info The file contains an unknown PE resource name possibly indicative of a packer
Network ET MALWARE [ANY.RUN] Win32/Gh0stRat Keep-Alive
Network ET MALWARE Backdoor family PCRat/Gh0st CnC traffic
Network ET MALWARE Backdoor family PCRat/Gh0st CnC traffic (OUTBOUND) 102
Network ET MALWARE Gh0st Remote Access Trojan Encrypted Session To CnC Server
No Category URL CC ASN Co Date
1c2http://23.224.239.91:123/US USCNSERVERS2024.09.04
2c2http://192.151.244.144:9090/US USCNSERVERS2024.02.06
No URL CC ASN Co Reporter Date
1http://18.143.169.29/abc.exe
backdoor exe ghostrat
SG SGAMAZON-02abus3reports2024.08.05
2http://60.204.249.34/1.exe
ghostrat trojan
CN CNTry02024.05.06
3http://60.204.249.34/23.exe
ghostrat trojan
CN CNTry02024.05.06
4http://82.157.254.217:8080/server1.exe
ghostrat
CN CNabus3reports2023.12.14
5http://82.157.254.217:8080/server.exe
ghostrat
CN CNabus3reports2023.12.14
View only the last 5
Beta Service, If you select keyword, you can check detailed information.