General

  • Target

    074eebf682d0ffdef806a3d796be37ef3a8446fcbdd9d58fe1a179757440d482_NeikiAnalytics.exe

  • Size

    2.0MB

  • Sample

    240629-2ha1bs1gpr

  • MD5

    80a5bc2e0cf87b36923e219b8148b470

  • SHA1

    41ca123fd83b956d5a7a1f5790010d78d0a92d0d

  • SHA256

    074eebf682d0ffdef806a3d796be37ef3a8446fcbdd9d58fe1a179757440d482

  • SHA512

    2c4f2c6b4f4f0cf7e1e6aad057f1d99febc6908279a46cd3dad84f955caf5e72b5c1884f71880b5ba9f059f3a7dd58b1a99db9c023e3b90934fb3c097f9a068e

  • SSDEEP

    24576:eO6zz/6vlUd1IMHr5RcsQ27BUMbYZwfeor2yD4yPyx8N8EFtCBOhKDAKtxAnoTZ3:el/AUdF16sQbam42np8NPkOuAKPW

Malware Config

Targets

    • Target

      074eebf682d0ffdef806a3d796be37ef3a8446fcbdd9d58fe1a179757440d482_NeikiAnalytics.exe

    • Size

      2.0MB

    • MD5

      80a5bc2e0cf87b36923e219b8148b470

    • SHA1

      41ca123fd83b956d5a7a1f5790010d78d0a92d0d

    • SHA256

      074eebf682d0ffdef806a3d796be37ef3a8446fcbdd9d58fe1a179757440d482

    • SHA512

      2c4f2c6b4f4f0cf7e1e6aad057f1d99febc6908279a46cd3dad84f955caf5e72b5c1884f71880b5ba9f059f3a7dd58b1a99db9c023e3b90934fb3c097f9a068e

    • SSDEEP

      24576:eO6zz/6vlUd1IMHr5RcsQ27BUMbYZwfeor2yD4yPyx8N8EFtCBOhKDAKtxAnoTZ3:el/AUdF16sQbam42np8NPkOuAKPW

    • Executes dropped EXE

    • Loads dropped DLL

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

    • Writes to the Master Boot Record (MBR)

      Bootkits write to the MBR to gain persistence at a level below the operating system.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Defense Evasion

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Discovery

Query Registry

1
T1012

System Information Discovery

1
T1082

Tasks