Analysis

  • max time kernel
    147s
  • max time network
    150s
  • platform
    windows10-2004_x64
  • resource
    win10v2004-20240508-en
  • resource tags

    arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system
  • submitted
    27-06-2024 04:15

General

  • Target

    4aeae4a1e8b70aac42015685e99c899574a8fd33340cd09111420e4a3b21454d_NeikiAnalytics.exe

  • Size

    198KB

  • MD5

    73f2025a3bd7a195b34956d9593e2290

  • SHA1

    ee0bfafa3e84fd0ef8bc5dc44c47e7a4065ef5cb

  • SHA256

    4aeae4a1e8b70aac42015685e99c899574a8fd33340cd09111420e4a3b21454d

  • SHA512

    20f2bb649b8c89d0f23679f6e74d49f3df3bce10178b87258e166f0db6e89e4b16fa370dbb6578a2e0fa8d75d0961d35f00eaa18c51c63d993096364b76a64b6

  • SSDEEP

    3072:9GJXWQh/x6wJXr8LOgWEQ0r8Hd33CvYFH7oyS:2FpPJXr0ln5lvYFH7oyS

Malware Config

Extracted

Family

cobaltstrike

C2

http://192.168.126.131:4444/ecNG

Attributes
  • user_agent

    User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SV1)

Signatures

Processes

  • C:\Users\Admin\AppData\Local\Temp\4aeae4a1e8b70aac42015685e99c899574a8fd33340cd09111420e4a3b21454d_NeikiAnalytics.exe
    "C:\Users\Admin\AppData\Local\Temp\4aeae4a1e8b70aac42015685e99c899574a8fd33340cd09111420e4a3b21454d_NeikiAnalytics.exe"
    1⤵
      PID:3624

    Network

    MITRE ATT&CK Matrix

    Replay Monitor

    Loading Replay Monitor...

    Downloads

    • memory/3624-0-0x000001F2E1FE0000-0x000001F2E1FE1000-memory.dmp
      Filesize

      4KB

    • memory/3624-1-0x00007FF7364C0000-0x00007FF7364EE000-memory.dmp
      Filesize

      184KB

    • memory/3624-13-0x00007FF7364C0000-0x00007FF7364EE000-memory.dmp
      Filesize

      184KB