General

  • Target

    c931a27d111f32674105713fdc964120_NeikiAnalytics.exe

  • Size

    19KB

  • Sample

    240517-hvflssfa64

  • MD5

    c931a27d111f32674105713fdc964120

  • SHA1

    2a280220c4a624e082a6131ef0baf470e737dc7c

  • SHA256

    22ee1bc310f8cca02975f01dcec46be2d779ebedf96e1732c34ec46c8a6216da

  • SHA512

    0cfbb967f3fdb6fae36d640ad955b5bf0e5a3b0b1b1c0683a5ebb49ea9f98221dbe0f8f5c7327c6f6a6a8e929396eb42fb265f3b5bee5c07a77db650abb641df

  • SSDEEP

    384:ZKRHBDj1y6sX7d/ZctaQTKfV1T6CSB8Oye3QBYLO0:URHBfCX7PcAD6CC8Oye3QaS0

Score
10/10

Malware Config

Targets

    • Target

      c931a27d111f32674105713fdc964120_NeikiAnalytics.exe

    • Size

      19KB

    • MD5

      c931a27d111f32674105713fdc964120

    • SHA1

      2a280220c4a624e082a6131ef0baf470e737dc7c

    • SHA256

      22ee1bc310f8cca02975f01dcec46be2d779ebedf96e1732c34ec46c8a6216da

    • SHA512

      0cfbb967f3fdb6fae36d640ad955b5bf0e5a3b0b1b1c0683a5ebb49ea9f98221dbe0f8f5c7327c6f6a6a8e929396eb42fb265f3b5bee5c07a77db650abb641df

    • SSDEEP

      384:ZKRHBDj1y6sX7d/ZctaQTKfV1T6CSB8Oye3QBYLO0:URHBfCX7PcAD6CC8Oye3QaS0

    Score
    10/10
    • Upatre

      Upatre is a generic malware downloader.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks