General

  • Target

    0ccd8ebf242998355d78e564b12ff183377a89c84cbd3478535e5e6155cb645e_NeikiAnalytics.exe

  • Size

    5.5MB

  • Sample

    240701-1n3rvswakk

  • MD5

    c4c696e6ea81e3e94050d4bfca2d4350

  • SHA1

    fbe76e557521504be389722ce25b4ad229ae2858

  • SHA256

    0ccd8ebf242998355d78e564b12ff183377a89c84cbd3478535e5e6155cb645e

  • SHA512

    1f2a0403bbcfdc1e7c501c87c8d0d1b352f21ac52001e0798e9aee5eabe4df734cfbd11201903fc8fb03918a6851aed695520da869b1559e4541a248eb7dacf4

  • SSDEEP

    98304:+iNCFT1fzFo347hHCbg1VD1e9HJlJCX4gqXv8wHtundQ+QCA86WLoz:+i4HLhHCIMHUcXEwgnmRj9Coz

Malware Config

Targets

    • Target

      0ccd8ebf242998355d78e564b12ff183377a89c84cbd3478535e5e6155cb645e_NeikiAnalytics.exe

    • Size

      5.5MB

    • MD5

      c4c696e6ea81e3e94050d4bfca2d4350

    • SHA1

      fbe76e557521504be389722ce25b4ad229ae2858

    • SHA256

      0ccd8ebf242998355d78e564b12ff183377a89c84cbd3478535e5e6155cb645e

    • SHA512

      1f2a0403bbcfdc1e7c501c87c8d0d1b352f21ac52001e0798e9aee5eabe4df734cfbd11201903fc8fb03918a6851aed695520da869b1559e4541a248eb7dacf4

    • SSDEEP

      98304:+iNCFT1fzFo347hHCbg1VD1e9HJlJCX4gqXv8wHtundQ+QCA86WLoz:+i4HLhHCIMHUcXEwgnmRj9Coz

    • Stops running service(s)

    • VMProtect packed file

      Detects executables packed with VMProtect commercial packer.

MITRE ATT&CK Matrix ATT&CK v13

Execution

System Services

1
T1569

Service Execution

1
T1569.002

Persistence

Create or Modify System Process

1
T1543

Windows Service

1
T1543.003

Privilege Escalation

Create or Modify System Process

1
T1543

Windows Service

1
T1543.003

Defense Evasion

Impair Defenses

1
T1562

Discovery

System Information Discovery

1
T1082

Impact

Service Stop

1
T1489

Tasks