General

  • Target

    3a5f0362b77cc6bdfb0870a47d073b70_NeikiAnalytics.exe

  • Size

    69KB

  • Sample

    240518-yb821abh9v

  • MD5

    3a5f0362b77cc6bdfb0870a47d073b70

  • SHA1

    843fc02b4c0a934747517e8bf931e0050ccae548

  • SHA256

    c36df1409e755916514e12e921a23465f2d8e75fe8d72477ea2a12d2818ec3fe

  • SHA512

    0bbf627056a3d8f5f0eeb6fdcf51fa0f5e046dd029d7d956e882a4a5da46f8db5b1342a97890b918d81eb69159f8919f248b56b198d57c8d16b510014595a664

  • SSDEEP

    1536:5Y9jw/dUT62rGdiUOWWrMffJ+AxM+I+ceWgP/KmVQz:5Y9CUT62/UOVMffJ+AW+I+cX

Score
10/10

Malware Config

Targets

    • Target

      3a5f0362b77cc6bdfb0870a47d073b70_NeikiAnalytics.exe

    • Size

      69KB

    • MD5

      3a5f0362b77cc6bdfb0870a47d073b70

    • SHA1

      843fc02b4c0a934747517e8bf931e0050ccae548

    • SHA256

      c36df1409e755916514e12e921a23465f2d8e75fe8d72477ea2a12d2818ec3fe

    • SHA512

      0bbf627056a3d8f5f0eeb6fdcf51fa0f5e046dd029d7d956e882a4a5da46f8db5b1342a97890b918d81eb69159f8919f248b56b198d57c8d16b510014595a664

    • SSDEEP

      1536:5Y9jw/dUT62rGdiUOWWrMffJ+AxM+I+ceWgP/KmVQz:5Y9CUT62/UOVMffJ+AW+I+cX

    Score
    10/10
    • Upatre

      Upatre is a generic malware downloader.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks