General

  • Target

    257e6f278410bb90796e13fff5ffcdf517d70114f6f84f8d5f07c3fb173b159a_NeikiAnalytics.exe

  • Size

    17KB

  • Sample

    240625-3qn3latcrl

  • MD5

    00756c5204a8ca3508da59e7b6d450c0

  • SHA1

    140ded063ac4ee2443f12097dc57b8b049b87695

  • SHA256

    257e6f278410bb90796e13fff5ffcdf517d70114f6f84f8d5f07c3fb173b159a

  • SHA512

    3b7ea9ff2a34ebc81e2d8aade6650d3056698965a6e90c93a62d67a4e76924701f9a4a1c2b1cafcf59ed2fc38abe4c93df56ebb42706c285abdcb2d3d33c2c71

  • SSDEEP

    192:4DMAe4Ckj19RZZ6wpSfu1bKcq5uHj7khBDSeKNH4EJ/CWcpBUbOj6kxiY:4DMAoKz6WtKEj7aBDizJaWwbAY

Malware Config

Extracted

Family

cobaltstrike

C2

http://192.168.136.129:8080/QLWi

Attributes
  • user_agent

    User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; Trident/4.0; .NET CLR 2.0.50727)

Targets

    • Target

      257e6f278410bb90796e13fff5ffcdf517d70114f6f84f8d5f07c3fb173b159a_NeikiAnalytics.exe

    • Size

      17KB

    • MD5

      00756c5204a8ca3508da59e7b6d450c0

    • SHA1

      140ded063ac4ee2443f12097dc57b8b049b87695

    • SHA256

      257e6f278410bb90796e13fff5ffcdf517d70114f6f84f8d5f07c3fb173b159a

    • SHA512

      3b7ea9ff2a34ebc81e2d8aade6650d3056698965a6e90c93a62d67a4e76924701f9a4a1c2b1cafcf59ed2fc38abe4c93df56ebb42706c285abdcb2d3d33c2c71

    • SSDEEP

      192:4DMAe4Ckj19RZZ6wpSfu1bKcq5uHj7khBDSeKNH4EJ/CWcpBUbOj6kxiY:4DMAoKz6WtKEj7aBDizJaWwbAY

MITRE ATT&CK Matrix

Tasks