General

  • Target

    0b0e4b42823a0ec876720b6a97c8032ea3792567b39229310904bc299a055744_NeikiAnalytics.exe

  • Size

    3.0MB

  • Sample

    240628-wypkrs1fjr

  • MD5

    8482ba6ed9487270d321cd0696ed3340

  • SHA1

    9f62169ee8e0d973f7e34dddc46c8b9dbafb8fd0

  • SHA256

    0b0e4b42823a0ec876720b6a97c8032ea3792567b39229310904bc299a055744

  • SHA512

    bf0831c4f6f3633b8cc2d2b2e1571297356547d630485f7c0bf56991839160ea5e88572820a54addf147714ef78bfad7cf2bba9520eaea217186b59b2bf61d61

  • SSDEEP

    98304:YhaIO2+Q/A1lzrqYo8I2TVquZLF8rimipmAFz/zW1:lDQPYnqWkimipmAZy

Malware Config

Extracted

Family

sality

C2

http://89.119.67.154/testo5/

http://kukutrustnet777.info/home.gif

http://kukutrustnet888.info/home.gif

http://kukutrustnet987.info/home.gif

Targets

    • Target

      0b0e4b42823a0ec876720b6a97c8032ea3792567b39229310904bc299a055744_NeikiAnalytics.exe

    • Size

      3.0MB

    • MD5

      8482ba6ed9487270d321cd0696ed3340

    • SHA1

      9f62169ee8e0d973f7e34dddc46c8b9dbafb8fd0

    • SHA256

      0b0e4b42823a0ec876720b6a97c8032ea3792567b39229310904bc299a055744

    • SHA512

      bf0831c4f6f3633b8cc2d2b2e1571297356547d630485f7c0bf56991839160ea5e88572820a54addf147714ef78bfad7cf2bba9520eaea217186b59b2bf61d61

    • SSDEEP

      98304:YhaIO2+Q/A1lzrqYo8I2TVquZLF8rimipmAFz/zW1:lDQPYnqWkimipmAZy

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Create or Modify System Process

1
T1543

Windows Service

1
T1543.003

Privilege Escalation

Create or Modify System Process

1
T1543

Windows Service

1
T1543.003

Abuse Elevation Control Mechanism

1
T1548

Bypass User Account Control

1
T1548.002

Defense Evasion

Modify Registry

5
T1112

Impair Defenses

4
T1562

Disable or Modify Tools

3
T1562.001

Disable or Modify System Firewall

1
T1562.004

Abuse Elevation Control Mechanism

1
T1548

Bypass User Account Control

1
T1548.002

Discovery

System Information Discovery

1
T1082

Tasks