General

  • Target

    26aac9ea66853d906d1e9470c9055190_NeikiAnalytics.exe

  • Size

    2.3MB

  • Sample

    240611-eehjnstarc

  • MD5

    26aac9ea66853d906d1e9470c9055190

  • SHA1

    4b362f8b638b01484a000fe47753ba442cff08cc

  • SHA256

    38d5c1f417fe5efe72c5bdd1ed614467d91d25801fda335f599922f0caec9778

  • SHA512

    c759c8c5d9b21b6faf1e60e82498e45c33906b2cd87f41b8ee99c52ec1018f639a4e921a0069246780cde0160f537f0aa89e94e3d8c2c233ea0e1217abe3d9c4

  • SSDEEP

    49152:oezaTF8FcNkNdfE0pZ9ozt4wIQlqOllgoJsT4gvmqGac:oemTLkNdfE0pZrQ1

Malware Config

Extracted

Family

gozi

Targets

    • Target

      26aac9ea66853d906d1e9470c9055190_NeikiAnalytics.exe

    • Size

      2.3MB

    • MD5

      26aac9ea66853d906d1e9470c9055190

    • SHA1

      4b362f8b638b01484a000fe47753ba442cff08cc

    • SHA256

      38d5c1f417fe5efe72c5bdd1ed614467d91d25801fda335f599922f0caec9778

    • SHA512

      c759c8c5d9b21b6faf1e60e82498e45c33906b2cd87f41b8ee99c52ec1018f639a4e921a0069246780cde0160f537f0aa89e94e3d8c2c233ea0e1217abe3d9c4

    • SSDEEP

      49152:oezaTF8FcNkNdfE0pZ9ozt4wIQlqOllgoJsT4gvmqGac:oemTLkNdfE0pZrQ1

    • Gozi

      Gozi is a well-known and widely distributed banking trojan.

    • xmrig

      XMRig is a high performance, open source, cross platform CPU/GPU miner.

    • XMRig Miner payload

    • Executes dropped EXE

    • Loads dropped DLL

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks