Gh0stCringe (Formerly CirenegRAT)
ID: f38b4ede-cb07-54f5-8b98-583d4b959518
STIX ID: report--f38b4ede-cb07-54f5-8b98-583d4b959518
Feed Name: Binary Defense Blog
This document is a concise opcode/command reference for a Windows remote-access malware module, listing functions such as obtaining SYSTEM privileges and shutdown, uninstall, registry modification, gathering and sending host information to C2, changing group IDs, deleting event logs, downloading/updating modules from C2, visible and covert URL opening, creating and executing files with supplied commands, displaying popups, enumerating processes and windows, loading proxy DLLs, and loading a keylogger plugin (including thread-based variants). The table highlights capabilities for privilege escalation, persistence, C2-driven modular updates, data capture (keylogging), and anti-forensics (event log removal).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
