{"id":283,"date":"2013-06-23T08:17:02","date_gmt":"2013-06-23T08:17:02","guid":{"rendered":"http:\/\/www.3lectrik.com\/normanshark\/?page_id=283"},"modified":"2013-06-23T08:17:02","modified_gmt":"2013-06-23T08:17:02","slug":"the-many-faces-of-gh0st-rat","status":"publish","type":"page","link":"https:\/\/www.3lectrik.com\/normanshark\/news-events\/press-releases\/the-many-faces-of-gh0st-rat\/","title":{"rendered":"The Many Faces of Gh0st Rat"},"content":{"rendered":"<div class=\"twelwe columns\">\n<h1>The Many Faces of Gh0st Rat<\/h1>\n<p><em><strong>Plotting the connections between malware attacks.<\/strong><\/em><\/p>\n<p>Snorre Fagerland, Principal Security Researcher<\/p>\n<p>Norman SharkA<\/p>\n<h2>Introduction<\/h2>\n<p>Gh0st Rat is a well-known Chinese remote access trojan which was originally made by C.Rufus Security Team several years ago. Just as with other well-featured \u201coff-the-shelf\u201d trojans like Poison Ivy, Hupigon and DarkComet it has been used by all sorts of people \u2013 from the script kiddie next door to resourceful targeted attack actors (1)<\/p>\n<p>Cybercriminals use off-the-shelf malware not only because it\u2019s easy and cheap. They also use it because it\u2019s hard to track. Anybody could use this malware, so the criminal could be anybody. However, this changes somewhat when they start modifying the code. The malware now becomes somewhat attributable and can be connected to known cases and criminal groups. This document is the result of examining selected common traits between some 1200+ Gh0st Rat program files (samples) with the help of Maltego, a tool to visualize data connections. The samples were processed by us in a timeframe of approximately six months, from August 2011 to February 2012.<\/p>\n<p>In this study we attempt to map out what logical connections do exist between different Gh0st botnet campaigns. This is important because it gives an indication of the scale of operation and sometimes what the aims of the campaigns are, and this can be valuable for risk analysis. Additional data produced by the study may be used for risk mitigation.<\/p>\n<p style=\"text-align: center;\">\n<section class=\"row\">\n<div class=\"twelve columns\">\n<h1>Contact Information<\/h1>\n<\/div>\n<\/section>\n<section class=\"row\">\n<div class=\"twelwe columns last\">\n<div class=\"rtf\">\n<div class=\"data\">\n<p>Stein Surlien, CEO Norman Shark<\/p>\n<p>Mob:+ 47 911 16\u00a0240 Email: <a  href=\"mailto:stein.surlien@norman.com\">stein.surlien@norman.com<\/a><\/p>\n<p>Isabella Alveberg, CMO Norman Shark<\/p>\n<p>Mob:+ 47\u00a0957 30\u00a0578 \u00a0Email: <a  href=\"mailto:isabella.alveberg@norman.com\">isabella.alveberg@norman.com<\/a><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/section>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>The Many Faces of Gh0st Rat Plotting the connections between malware attacks. Snorre Fagerland, Principal Security Researcher Norman SharkA Introduction Gh0st Rat is a well-known Chinese remote access trojan which was originally made by C.Rufus Security Team several years ago. Just as with other well-featured \u201coff-the-shelf\u201d trojans like Poison Ivy, Hupigon and DarkComet it has [&hellip;]<\/p>\n","protected":false},"author":15,"featured_media":0,"parent":66,"menu_order":0,"comment_status":"open","ping_status":"open","template":"","meta":{"footnotes":""},"class_list":["post-283","page","type-page","status-publish","hentry"],"jetpack_shortlink":"https:\/\/wp.me\/P5TlPb-4z","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/pages\/283","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/comments?post=283"}],"version-history":[{"count":2,"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/pages\/283\/revisions"}],"predecessor-version":[{"id":285,"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/pages\/283\/revisions\/285"}],"up":[{"embeddable":true,"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/pages\/66"}],"wp:attachment":[{"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/media?parent=283"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}