General

  • Target

    16ae0aa2c1269316be210abd46059fa0_NeikiAnalytics.exe

  • Size

    4KB

  • Sample

    240527-b7gajabh8x

  • MD5

    16ae0aa2c1269316be210abd46059fa0

  • SHA1

    2bd1032db6cd62542b816dbd0afd7eff7f54d698

  • SHA256

    ad2f173f03d0d3fcabd2e12751b59356b572c64b74441c61c0ceb38396fc26c5

  • SHA512

    955dd0945296681108cdcb5556620400beaedddbb9c35dc88d80f2889d649f6b8872c7f8dce7bd7080cc08c0f27411ae3b3ed74b797e1e7546463e3f9306f50a

  • SSDEEP

    48:Zdni+Wyi18DN0nCvTaE6nc9fhXcGEY3sJd9ga91RsKs+EOnA7B8mOo4jUx7OtKGc:Z0v4mUWKh9ctgC1RMJOnKymV44Sh

Score
10/10

Malware Config

Targets

    • Target

      16ae0aa2c1269316be210abd46059fa0_NeikiAnalytics.exe

    • Size

      4KB

    • MD5

      16ae0aa2c1269316be210abd46059fa0

    • SHA1

      2bd1032db6cd62542b816dbd0afd7eff7f54d698

    • SHA256

      ad2f173f03d0d3fcabd2e12751b59356b572c64b74441c61c0ceb38396fc26c5

    • SHA512

      955dd0945296681108cdcb5556620400beaedddbb9c35dc88d80f2889d649f6b8872c7f8dce7bd7080cc08c0f27411ae3b3ed74b797e1e7546463e3f9306f50a

    • SSDEEP

      48:Zdni+Wyi18DN0nCvTaE6nc9fhXcGEY3sJd9ga91RsKs+EOnA7B8mOo4jUx7OtKGc:Z0v4mUWKh9ctgC1RMJOnKymV44Sh

    Score
    10/10
    • Upatre

      Upatre is a generic malware downloader.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Deletes itself

    • Executes dropped EXE

    • Loads dropped DLL

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks