Rewterz
Rewterz Threat Advisory – CVE-2022-3980 – Sophos Mobile External Vulnerability
December 8, 2022
Rewterz
Rewterz Threat Alert – Phobos Ransomware – Active IOCs
December 9, 2022

Rewterz Threat Alert – Ghost RAT – Active IOCs

Severity

Medium

Analysis Summary

Ghost RAT is a remote access trojan that allows an attacker to access an infected machine to harvest sensitive information and data. This type of malware enables cybercriminals to gain complete access to infected computers and attempt to hijack the user’s banking account.Some variants of Gh0st can be used to install cryptocurrency miners and/or various trojan-type programs. Cybercriminals use these controls over the infected computer to access the victim’s bank account and transfer money without authorization.

Impact

  • Credential Theft
  • Unauthorized Access
  • Theft of Sensitive Information
  • File manipulation
  • Remote command execution

Indicators of Compromise

MD5

  • ad8b2752f73a9799e19ac396e5890f27
  • 0712a2f7a4cafd566bb0ec2f77c647ff
  • a9a5fd9e81bf95ef0ca75219b25a4fa5

SHA-256

  • dada3acaab4f82f17d2d481403cc9b7b81e2d425a92e89172742fa4875243ecf
  • 5d92d55400ab9e837ce7192a3d899ba39efe3dbe1164ae339f06173aff5e2c39
  • 38d75e5659fd0bd1bdef9676cf80ce5331b759bec33c7e5a4c55db73ef2c8d80

SHA-1

  • 429c13a4cc2527018b43179c502965e79071287c
  • bf941620852150e7d3b377055dc91a1f71c3dad0
  • 1082bdf4db2758cf949908f231c6cdf7ebf43064

Remediation

  • Block all threat indicators at your respective controls.
  • Search for IOCs in your environment.