Cert Graveyard Report

Certificate Signer: Xiamen Jisou Network Technology Co., Ltd.
Certificate Serial: 24 FF 66 39 95 3E 1D 11 61 AF 67 0E 86 17 7E F0

All Cert Graveyard entries are considered malware. Other files by the same certificate serial number should be considered suspect.
Golden Gh0st Loader
Remote access tool
1f8fbdce2b257b817f8a1c6a8e8703fc3ebbab49df8bc4b41cd12cd76eaf2288
24 FF 66 39 95 3E 1D 11 61 AF 67 0E 86 17 7E F0
Xiamen Jisou Network Technology Co., Ltd.
Sectigo Public Code Signing CA EV R36
2026-04-01 00:00:00
2027-04-01 23:59:00
2026-07-04 09:55:46 UTC
This file was found during our investigation and had the following suspicious indicators:  - The file triggered the following high IDS rules:    - ET MALWARE GoldenGh0stLoader Websocket Checkin - C2 Response The sample is communicating with "hxxp[://]api[.]keensie[.]com:5198" , which was previously used by another sample of Zhong Stealer malware that had a certificate that has since been revoked ("Biao Zhao" sha256:cb33dc853996d06b0282e1795d9d550232032178cf071a1c3404953e102b3ffa).