# Gh0stRat

**URL:** <https://community.emergingthreats.net/t/gh0strat/1017>\
**Category:** Rule Signatures\
**Created:** [October 6, 2023, 5:20pm UTC](https://community.emergingthreats.net/t/gh0strat/1017 "2023-10-06T17:20:58Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jane0sint](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/jane0sint/32/398_2.png) [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)\
**Post date:** [October 6, 2023, 5:20pm UTC](https://community.emergingthreats.net/t/gh0strat/1017/1 "2023-10-06T17:20:59Z")

</div>

Hi!  
We’ve got another gh0st, and here is the rule for it, built according to the template of the previous one sid:2048128 from @naumovax.

```auto
alert tcp-pkt $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE [ANY.RUN] Win32/Gh0stRat Activity";
flow:established,to_server;
content:"|32 00 32 00 32 00 32 00 00 00|"; depth:25; fast_pattern;
content:"|78 9c|"; distance:4; within:2;
classtype: trojan-activity;
reference:md5,0d5e3beb1a973c68180cdc7b4c9be36b;
reference:url,app.any.run/tasks/bff76d98-1ed4-4503-a21b-7735bb0b7907;
sid: 1; rev: 1;)

```

Look at the traffic for new ideas,

> **[Analysis 采购卡头.exe (MD5: DE15E8002451F23C7F849B39FF2EB938) Malicious activity...](https://app.any.run/tasks/a7d9af4e-7c0e-4bc1-844a-cef9b3ac3617/)**
>
> Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.

for example, I got the idea to write about 1 byte content in the archive from the server.

```auto
alert tcp-pkt $EXTERNAL_NET any -> $HOME_NET any (msg:"ET MALWARE [ANY.RUN] Win32/Gh0stRat Keep-Alive";
flow:established,to_client; 
dsize: <56;
content:"|00 0000 0100 0000 789c|"; depth: 24;
isdataat: !56;
classtype: trojan-activity;
reference:md5,0d5e3beb1a973c68180cdc7b4c9be36b;
reference:url,app.any.run/tasks/bff76d98-1ed4-4503-a21b-7735bb0b7907;
sid: 2; rev: 1;)

```

Best regards, Jane ೀ⋆｡🌷

---

<div class="post-metadata">

**Author:** ![ishaughnessy](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/ishaughnessy/32/491_2.png) [@ishaughnessy](https://community.emergingthreats.net/u/ishaughnessy)\
**Post date:** [October 6, 2023, 9:53pm UTC](https://community.emergingthreats.net/t/gh0strat/1017/2 "2023-10-06T21:53:08Z")

</div>

Awesome work @Jane0sint ! Here are those sids, have a great weekend!

```auto
2048477 - [ANY.RUN] Win32/Gh0stRat Activity 
2048478 - [ANY.RUN] Win32/Gh0stRat Keep-Alive 

```

---

<div class="post-metadata">

**Author:** ![Jane0sint](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/jane0sint/32/398_2.png) [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)\
**Post date:** [December 28, 2023, 8:28am UTC](https://community.emergingthreats.net/t/gh0strat/1017/3 "2023-12-28T08:28:49Z")

</div>

Hi, can I ask you to add a link to this discussion in the rules 2048477 2048478?  
reference:url,[community.emergingthreats.net/t/gh0strat/](http://community.emergingthreats.net/t/gh0strat/);  
Sorry for the spam 🙇‍♀️

---

<div class="post-metadata">

**Author:** ![jtaylor](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/jtaylor/32/12_2.png) [@jtaylor](https://community.emergingthreats.net/u/jtaylor)\
**Post date:** [December 28, 2023, 7:06pm UTC](https://community.emergingthreats.net/t/gh0strat/1017/4 "2023-12-28T19:06:48Z")

</div>

Updated signatures will go out today! Thanks!

JT
