General

  • Target

    32420426edd70b45ac99eb1e7f20424b0f6a8fa2acb20507ac26ef41875601f9_NeikiAnalytics.exe

  • Size

    986KB

  • Sample

    240701-d22emaybln

  • MD5

    a6ae11acddeabaa1d8c2031a72c62140

  • SHA1

    977c42d35f953557f9fd8ba7fae46bab2293efcf

  • SHA256

    32420426edd70b45ac99eb1e7f20424b0f6a8fa2acb20507ac26ef41875601f9

  • SHA512

    457cade4cd7f54bf5a483fc5149d48e0e1cd35d876267fad88952d4fd19f82bbaa24300c516be62313c6d8a2951cb0553db8a460b6a5e0ac87586cda3a983f81

  • SSDEEP

    24576:sWkWmI1D/H3B2TZSKjhqNSV2HyGqi0zkcB2SEmH0:BBmg/XB2QKF2HmDzkcDED

Malware Config

Targets

    • Target

      32420426edd70b45ac99eb1e7f20424b0f6a8fa2acb20507ac26ef41875601f9_NeikiAnalytics.exe

    • Size

      986KB

    • MD5

      a6ae11acddeabaa1d8c2031a72c62140

    • SHA1

      977c42d35f953557f9fd8ba7fae46bab2293efcf

    • SHA256

      32420426edd70b45ac99eb1e7f20424b0f6a8fa2acb20507ac26ef41875601f9

    • SHA512

      457cade4cd7f54bf5a483fc5149d48e0e1cd35d876267fad88952d4fd19f82bbaa24300c516be62313c6d8a2951cb0553db8a460b6a5e0ac87586cda3a983f81

    • SSDEEP

      24576:sWkWmI1D/H3B2TZSKjhqNSV2HyGqi0zkcB2SEmH0:BBmg/XB2QKF2HmDzkcDED

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Adds Run key to start application

    • Enumerates connected drives

      Attempts to read the root path of hard drives other than the default C: drive.

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Credential Access

Unsecured Credentials

1
T1552

Credentials In Files

1
T1552.001

Discovery

Query Registry

2
T1012

System Information Discovery

3
T1082

Peripheral Device Discovery

1
T1120

Collection

Data from Local System

1
T1005

Tasks