PULSE NAME
Tracking & Detecting GhostSocks Malware
WHITE CyberHunter_NL 2026-03-31 Modified: 2026-03-31
19
IOCs
MEDIUM VOLUME
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (19)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 IPv4 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
CVE CVE-2026-1731 2026-03-31
FileHash-MD5 ddd2994acd25bde5ac32a03f1cf30b41 MD5 of 9b90c62299d4bed2e0752e2e1fc777ac50308534 2026-03-31
FileHash-SHA1 10f928e00a1ed0181992a1e4771673566a02f4e3 2026-03-31
FileHash-SHA1 3d9d7a7905e46a3e39a45405cb010c1baa735f9e 2026-03-31
FileHash-SHA1 9b90c62299d4bed2e0752e2e1fc777ac50308534 2026-03-31
FileHash-SHA256 59312a8d6663c9a404d0b5aa96b70be3946592e5c5489366e04114b11a722fa1 SHA256 of 9b90c62299d4bed2e0752e2e1fc777ac50308534 2026-03-31
FileHash-SHA256 fab6525bf6e77249b74736cb74501a9491109dc7950688b3ae898354eb920413 2026-03-31
IPv4 159.89.46.92 CC=US ASN=AS14061 digitalocean llc 2026-03-31
IPv4 23.106.58.48 CC=GB ASN=AS205544 leaseweb uk limited 2026-03-31
IPv4 86.54.24.29 CC=GB ASN=AS206509 kcom group limited 2026-03-31
URL http://86.54.24.29/Renewable.exe 2026-03-31
URL https://bloo.io/research/malware/ghostsocks 2026-03-31
URL https://synthient.com/blog/ghostsocks-from-initial-access-to-residential-proxy 2026-03-31
domain alltipi.com 2026-03-31
domain bloo.io 2026-03-31
domain retreaw.click 2026-03-31
domain synthient.com 2026-03-31
hostname w2.bruggebogeyed.site 2026-03-31
hostname www.lbfs.site 2026-03-31