This file was found during our investigation and had the following suspicious indicators:
- The file triggered the following high IDS rules:
- ET MALWARE GoldenGh0stLoader Websocket Checkin - C2 Response
The sample is communicating with "hxxp[://]api[.]keensie[.]com:5198" , which was previously used by another sample of Zhong Stealer malware that had a certificate that has since been revoked ("Biao Zhao" sha256:cb33dc853996d06b0282e1795d9d550232032178cf071a1c3404953e102b3ffa).