General

  • Target

    1db4920f417fdc928d6fd1e9b29c7def950d0b198ea261946aced53bbd82f120_NeikiAnalytics.exe

  • Size

    899KB

  • Sample

    240630-1zc1ksxang

  • MD5

    72ca27e549045bc4ad9e5670827b5790

  • SHA1

    bea2ab31d1f0936c0a8bedbe1858f76dbaf910d7

  • SHA256

    1db4920f417fdc928d6fd1e9b29c7def950d0b198ea261946aced53bbd82f120

  • SHA512

    b33b7029d61f8b549098cd7bef2586c90210ed6d44639b91d5b3503e1498b7a2e05844adcf081d3f82ebcbca027fcde5964e4f6fdf2a03bca09a78ee58c3280f

  • SSDEEP

    24576:7V2bG+2gMir4fgt7ibhRM5QhKehFdMtRj7nH1PXo:7wqd87Vo

Score
10/10

Malware Config

Extracted

Family

gh0strat

C2

hackerinvasion.f3322.net

Targets

    • Target

      1db4920f417fdc928d6fd1e9b29c7def950d0b198ea261946aced53bbd82f120_NeikiAnalytics.exe

    • Size

      899KB

    • MD5

      72ca27e549045bc4ad9e5670827b5790

    • SHA1

      bea2ab31d1f0936c0a8bedbe1858f76dbaf910d7

    • SHA256

      1db4920f417fdc928d6fd1e9b29c7def950d0b198ea261946aced53bbd82f120

    • SHA512

      b33b7029d61f8b549098cd7bef2586c90210ed6d44639b91d5b3503e1498b7a2e05844adcf081d3f82ebcbca027fcde5964e4f6fdf2a03bca09a78ee58c3280f

    • SSDEEP

      24576:7V2bG+2gMir4fgt7ibhRM5QhKehFdMtRj7nH1PXo:7wqd87Vo

    Score
    10/10
    • Gh0st RAT payload

    • Gh0strat

      Gh0st RAT is a remote access tool (RAT) with its source code public and it has been used by multiple Chinese groups.

MITRE ATT&CK Matrix

Tasks