General

  • Target

    5327b43596752617c77034bdb5ef8750_NeikiAnalytics.exe

  • Size

    4KB

  • Sample

    240602-jjdhqsfb5y

  • MD5

    5327b43596752617c77034bdb5ef8750

  • SHA1

    7972459b05aeb43103e464d3dd17987b1a964b45

  • SHA256

    2167013900ec7ea8257d1d802677d855b14815f2200510ec8e3ea8fe071c1351

  • SHA512

    2421d4fbeb2b0128bb55a99e5ddf9eb817eafc0832b8a6fed028d291a08c9a99c1220381e097114089dbbc04beefce87aac0bce29f9b15eafb4def058667be5f

  • SSDEEP

    48:Zdni+Wyi18DN0nCvTaE6nc9fhXcGEY3sJd9ga91RsKKCnA7B8mOo4jUx7OtKGcQx:Z0v4mUWKh9ctgC1Rd5nKymV44Sh/7

Score
10/10

Malware Config

Targets

    • Target

      5327b43596752617c77034bdb5ef8750_NeikiAnalytics.exe

    • Size

      4KB

    • MD5

      5327b43596752617c77034bdb5ef8750

    • SHA1

      7972459b05aeb43103e464d3dd17987b1a964b45

    • SHA256

      2167013900ec7ea8257d1d802677d855b14815f2200510ec8e3ea8fe071c1351

    • SHA512

      2421d4fbeb2b0128bb55a99e5ddf9eb817eafc0832b8a6fed028d291a08c9a99c1220381e097114089dbbc04beefce87aac0bce29f9b15eafb4def058667be5f

    • SSDEEP

      48:Zdni+Wyi18DN0nCvTaE6nc9fhXcGEY3sJd9ga91RsKKCnA7B8mOo4jUx7OtKGcQx:Z0v4mUWKh9ctgC1Rd5nKymV44Sh/7

    Score
    10/10
    • Upatre

      Upatre is a generic malware downloader.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks