Common Information
Type Value
Value
rule Windows_Trojan_GHOSTPULSE_2 {
	meta:
		author = "Elastic Security"
		creation_date = "2024-10-10"
		last_modified = "2024-10-10"
		os = "Windows"
		arch = "x86"
		category_type = "Trojan"
		family = "GHOSTPULSE"
		threat_name = "Windows.Trojan.GHOSTPULSE"
		license = "Elastic License v2"
	strings:
		$a1 = { 48 83 EC 18 C7 04 24 00 00 00 00 8B 04 24 48 8B 4C 24 20 0F B7 04 41 85 C0 74 0A 8B 04 24 FF C0 89 04 24 EB E6 C7 44 24 08 00 00 00 00 8B 04 24 FF C8 8B C0 48 8B 4C 24 20 0F B7 04 41 83 F8 5C }
	condition:
		all of them
}
Category
Type Yara Rule
Misp Type
Description
Details Published Attributes CTI Title
Details Website 2024-10-19 16 Tricks and Treats: GHOSTPULSE’s new pixel-level deception — Elastic Security Labs