General

  • Target

    451b6e6869ee29dc55e128a2e2a9fd80_NeikiAnalytics.exe

  • Size

    4KB

  • Sample

    240526-bfvnvahg72

  • MD5

    451b6e6869ee29dc55e128a2e2a9fd80

  • SHA1

    c9a39942ffbe59840908477a2770e717bee6275c

  • SHA256

    034d82fa8a21906c8c21711eeab4dcfa77206ec5a8e1a181e5cf273fed0082f3

  • SHA512

    26ef8306e2d600c6b7a6a0f18dc8ac6ff15c27a75d53c47b7738faa27ab3b2998614e834344b13af0d6afaf94fd2b36bcac8050ad425ba046c96c65bc548e5c7

  • SSDEEP

    48:Zdni+Wyi18DN0nCvTaE6nc9fhXcGEY3sJd9ga91RsOIg2nA7B8mOo4jUx7OtKGc:Z0v4mUWKh9ctgC1RVITnKymV44Sh

Score
10/10

Malware Config

Targets

    • Target

      451b6e6869ee29dc55e128a2e2a9fd80_NeikiAnalytics.exe

    • Size

      4KB

    • MD5

      451b6e6869ee29dc55e128a2e2a9fd80

    • SHA1

      c9a39942ffbe59840908477a2770e717bee6275c

    • SHA256

      034d82fa8a21906c8c21711eeab4dcfa77206ec5a8e1a181e5cf273fed0082f3

    • SHA512

      26ef8306e2d600c6b7a6a0f18dc8ac6ff15c27a75d53c47b7738faa27ab3b2998614e834344b13af0d6afaf94fd2b36bcac8050ad425ba046c96c65bc548e5c7

    • SSDEEP

      48:Zdni+Wyi18DN0nCvTaE6nc9fhXcGEY3sJd9ga91RsOIg2nA7B8mOo4jUx7OtKGc:Z0v4mUWKh9ctgC1RVITnKymV44Sh

    Score
    10/10
    • Upatre

      Upatre is a generic malware downloader.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Deletes itself

    • Executes dropped EXE

    • Loads dropped DLL

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks