General

  • Target

    32b0788f999b72b8293db9bd37e3f9d1ae96cf78b2f5274778e548a18b05746b_NeikiAnalytics.exe

  • Size

    1.8MB

  • Sample

    240701-d7gbmsycmk

  • MD5

    ec73c076129b8d2186e8ef0a943e0110

  • SHA1

    6a226b5220c162252afc483ffc5a61399657efe8

  • SHA256

    32b0788f999b72b8293db9bd37e3f9d1ae96cf78b2f5274778e548a18b05746b

  • SHA512

    e4104e5b5c2e0c360f531e6841ccce742b51a7e151cf616726940008c7c262fcc9742430c1ebf354b546154435134419d31ea1e69029094b799e5b7d83560486

  • SSDEEP

    49152:hAj266+3GWD8ZHsh3+7+cyXz9mX0d0DkSx92/+OAaQl:6N3dva0dU2/O/l

Malware Config

Targets

    • Target

      32b0788f999b72b8293db9bd37e3f9d1ae96cf78b2f5274778e548a18b05746b_NeikiAnalytics.exe

    • Size

      1.8MB

    • MD5

      ec73c076129b8d2186e8ef0a943e0110

    • SHA1

      6a226b5220c162252afc483ffc5a61399657efe8

    • SHA256

      32b0788f999b72b8293db9bd37e3f9d1ae96cf78b2f5274778e548a18b05746b

    • SHA512

      e4104e5b5c2e0c360f531e6841ccce742b51a7e151cf616726940008c7c262fcc9742430c1ebf354b546154435134419d31ea1e69029094b799e5b7d83560486

    • SSDEEP

      49152:hAj266+3GWD8ZHsh3+7+cyXz9mX0d0DkSx92/+OAaQl:6N3dva0dU2/O/l

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Adds Run key to start application

    • Enumerates connected drives

      Attempts to read the root path of hard drives other than the default C: drive.

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Credential Access

Unsecured Credentials

1
T1552

Credentials In Files

1
T1552.001

Discovery

Query Registry

1
T1012

Peripheral Device Discovery

1
T1120

System Information Discovery

2
T1082

Collection

Data from Local System

1
T1005

Tasks