PULSE NAME
Introducing Gh0stGambit: A Dropper for Deploying Gh0st RAT
WHITE AlienVault 2024-07-31 Modified: 2024-08-30
15
IOCs
MEDIUM VOLUME
This analysis examines a recent malware campaign involving a dropper dubbed Gh0stGambit, which is employed to retrieve and execute encrypted payloads, specifically a variant of the notorious Gh0st Remote Access Trojan (RAT). The report details the multi-stage infection process, including the use of deceptive Chrome installer lures, the dropper's evasive techniques, and the capabilities of the delivered Gh0st RAT variant. The malware exhibits advanced functionality, such as rootkit components, keylogging, process termination, and data exfiltration. The investigation concludes that the campaign primarily targets Chinese-speaking users, based on the use of Chinese web lures and the malware's ability to gather information from Chinese applications.
Indicators of Compromise (15)
All CVE FileHash-MD5 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
CVE CVE-2024-5806 2024-07-31
FileHash-MD5 1577ad0ef0cc41b6e830c2c60821daa0 2024-07-31
FileHash-MD5 1e7dccdacced54c5d3515c2d6f5b9f00 2024-07-31
FileHash-MD5 4bf494f15fcc172b98abeb5a02ecffed 2024-07-31
FileHash-MD5 778d517a9de9b93f02e92602f1cfcd6c 2024-07-31
FileHash-MD5 82408e48f97f6c41b825b97a2e026831 2024-07-31
FileHash-MD5 af2debe45edd4a10a07b2afeec81bf87 2024-07-31
FileHash-MD5 d96a742899aeab9eaba691861908e316 2024-07-31
FileHash-MD5 dcadba35680a03e44d91191d0d9a4d47 2024-07-31
FileHash-MD5 fc6993a5498a7af0eab9899d86e393e5 2024-07-31
URL http://pplilv.bond/d4/107.148.73.225/code32 2024-07-31
URL http://pplilv.bond/d4/107.148.73.225/reg32 2024-07-31
domain chrome-web.com 2024-07-31
domain pplilv.bond 2024-07-31
hostname hacker.heikeniubi.buzz 2024-07-31