|
|
Ghost RAT Information
| Name: |
Ghost |
| Category: |
RAT |
| Alias: |
- Alias: BackDoor-J, Backdoor.DeepThroat.g |
| Advice: |
Remove |
| Risk: |
Elevated Risk
Elevated threats are usually threats that fall into the range of adware in which data about a user's habits are tracked and sent back to a server for analysis without your consent or knowledge. |
| Description:
|
|
| Signatures:
|
process: ghost.exe: MD5 Hash: f0ad30a284264138b28...
process: server.exe: MD5 Hash: 9b6ecdc27259a5cd275...
process: ghost.exe: MD5 Hash: 929b97d9229258616fe...
process: ghostservereditor.exe: MD5 Hash: 67a01da0294e642f4fa...
process: server.exe: MD5 Hash: 676acdb2b54c9a7b721...
process: binder.exe: MD5 Hash: 9f93d745496a2d50b81...
process: ghost.exe: MD5 Hash: 33bd1c76a226848fb49...
process: ghostservereditor.exe: MD5 Hash: c11fc1cfa8e2361ae49...
process: server.exe: MD5 Hash: 4b24a3c0724b1fd2f7d...
process: binder.exe: MD5 Hash: 5d356fa398465bec67a...
process: binder.exe: MD5 Hash: 841c27685304241bbf0...
process: ghost.exe: MD5 Hash: 86dcb670bb3e41662c0...
process: ghost.exe: MD5 Hash: 7eba1873181e021795e...
process: ghostservereditor.exe: MD5 Hash: d403c58383603fb7bfc...
process: server.exe: MD5 Hash: f80092671640ce5419c...
process: winsck_droper.exe: MD5 Hash: cb92817f836d094cfee...
process: ghost.exe: MD5 Hash: c42bc10c25adab98992...
process: ghostserver.exe: MD5 Hash: 5db0f9217e75de737e0...
process: mini-server.exe: MD5 Hash: efab0f9e334079ddd53...
process: clientghost.exe: MD5 Hash: 4e71e2cd0dd66df4dce...
process: notepad.exe: MD5 Hash: 6daf6ed05ac28bdcfd5...
process: run_cd.exe: MD5 Hash: ...
process: run_cd.exe: MD5 Hash: .. |
| Type: |
RAT - A Remote Administration Tool (RAT) is a Trojan type of software that when run, provides an attacker with the capability of remotely controlling a user's computer (victim) over the Internet. The attacker usually has full access to functions on the victim's computer. The victim's computer usually listens on the Internet for the attacker's commands. |
Top RAT Visited Pages:
SubSeven - Alias: BackDoor-G22, BackDoor-Sub7 - 291 visits
NetBus v.1.70 - 207 visits
The Prayer - Alias: BackDoor-DI, Backdoor.Prayer.15 - 75 visits
Cyrex msn trojan - Alias: BackDoor-AOB, Backdoor.VB.dm, Backdoor.VB.dm, Cyrex msn trojan, W32/Delf.B - 69 visits
Global Killer - Alias: Backdoor.GlobalKiller 1.0, Global Killer 1.0 - 54 visits
Systray BackDoor - 52 visits
AutoSpY - Alias: Backdoor.AutoSpy - 47 visits
Secret Agent - Alias: Backdoor.Antinuke.10, Secret Agent 1.0 - 46 visits
Netbus - Alias: Backdoor.Netbus - 41 visits
Undetected - Alias: Backdoor.tds.4f, Backdoor.tds.se.23, Backdoor.tds.se.23a, Backdoor.tds.se.30, Backdoor.TDS.SE.31, Ba - 40 visits
Random RAT Pages:
Net Raider - Alias: Backdoor.Netraider
Orion - Alias: Backdoor.Orion
ShockRave - Alias: BackDoor-AJ, Backdoor.Bowl, Bowl 1.0 Trojan, W32/Bowl
NT Remote Controller 2000
Remod - Alias: Backdoor.Remod.10, Remod 1.0
FraggleRock - Alias: BackDoor-LT, Backdoor.FR.155, Backdoor.Fraggle.143, Backdoor.Fraggle.144, Backdoor.Fraggle.150, Back
Back Orifice 2000 v1.0
XTCP
Serveme - Alias: BackDoor-VV, Backdoor.ServeMe
Cold Client Server - Alias: BackDoor-J, Backdoor.DeepThroat.g
|
|