BlackTech__2021__Malware_Gh0stTimes_Used_by_BlackTech_-_JPCERT_CC_Eyes_JPCERT_Coordination_Center_official_Blog.pdf
ID: b265cf03-8025-4194-8ad0-198c1f774d51
STIX ID: report--b265cf03-8025-4194-8ad0-198c1f774d51
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2021-10-05
Last Modified Date: 2021-10-05
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
JPCERT/CC provides a technical analysis of Gh0stTimes (a Ghost RAT derivative) used by the BlackTech APT: detailing its custom C2 protocol (ID/key exchange, XOR/RC4+zlib payloads), command modules (FileManager, ShellManager, PortmapManager, UltraPortmapManager), control-panel screenshots ("Times v1.2"), dummy code samples, Python decoding example, and an appendix of IoCs (C2 domains/IPs and malware hashes) to aid detection and response.
