General

  • Target

    1ad11b6018ce0f07bc70145b4322c2d79ce24c1661d42d09b2155ef94362be15_NeikiAnalytics.exe

  • Size

    899KB

  • Sample

    240630-z8bcnsyhlp

  • MD5

    7312957534e2813f63cf151e560b6de0

  • SHA1

    6696e0d445c03b29b00a50bf3c78a84100c02bb5

  • SHA256

    1ad11b6018ce0f07bc70145b4322c2d79ce24c1661d42d09b2155ef94362be15

  • SHA512

    1a81ea650c4d922262fa41def7df22eb58852e629c697d7df435223bdc404daf248099b576dff3998f01f44b01bc7ecedcb53896266f557c82afdc0c41228d84

  • SSDEEP

    24576:7V2bG+2gMir4fgt7ibhRM5QhKehFdMtRj7nH1PXu:7wqd87Vu

Score
10/10

Malware Config

Extracted

Family

gh0strat

C2

hackerinvasion.f3322.net

Targets

    • Target

      1ad11b6018ce0f07bc70145b4322c2d79ce24c1661d42d09b2155ef94362be15_NeikiAnalytics.exe

    • Size

      899KB

    • MD5

      7312957534e2813f63cf151e560b6de0

    • SHA1

      6696e0d445c03b29b00a50bf3c78a84100c02bb5

    • SHA256

      1ad11b6018ce0f07bc70145b4322c2d79ce24c1661d42d09b2155ef94362be15

    • SHA512

      1a81ea650c4d922262fa41def7df22eb58852e629c697d7df435223bdc404daf248099b576dff3998f01f44b01bc7ecedcb53896266f557c82afdc0c41228d84

    • SSDEEP

      24576:7V2bG+2gMir4fgt7ibhRM5QhKehFdMtRj7nH1PXu:7wqd87Vu

    Score
    10/10
    • Gh0st RAT payload

    • Gh0strat

      Gh0st RAT is a remote access tool (RAT) with its source code public and it has been used by multiple Chinese groups.

MITRE ATT&CK Matrix

Tasks