Malware Signature

The following table shows a list of malware samples and the corresponding botnet C&C (ip:port) associated with Gh0stRAT

Database Entry


Malware:Gh0stRAT
First seen:2020-12-25 21:20:04 UTC
Last seen:never

Malware Samples


The table below documents all malware samples associated with this malware family.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2020-12-25 21:20:040cc1d1fc0074b6d8545ea97c78ac5b39Virustotal results 61 / 71 (85.92%) Gh0stRAT101.226.26.166:443
2020-12-25 21:20:040cc1d1fc0074b6d8545ea97c78ac5b39Virustotal results 61 / 71 (85.92%) Gh0stRAT101.226.26.166:443