General

  • Target

    32ccf050962266df4e8cec7fdafcfae0f2218c886057654fe0a2e77b18286896_NeikiAnalytics.exe

  • Size

    280KB

  • Sample

    240701-d8ty5aycpl

  • MD5

    73e4408fdaf79d788db02cbdc79b90c0

  • SHA1

    c327a1b6c0f789c425a525d8ea1e7e066ebbc08f

  • SHA256

    32ccf050962266df4e8cec7fdafcfae0f2218c886057654fe0a2e77b18286896

  • SHA512

    8d1db8e4dc43a5ca3feb886c426dff4086c2d36c047ce04a89d7395e90f00de9c195d62ea43ecfe23b19e9be9f62c5c5ad20b50062b171fcbac88c9de457eb15

  • SSDEEP

    3072:Ho/xJw8BsAIm1Yo4hZK7xVG9Btj676ZBI:Ho/xJwIGoqZo4tjS6Y

Score
10/10

Malware Config

Targets

    • Target

      32ccf050962266df4e8cec7fdafcfae0f2218c886057654fe0a2e77b18286896_NeikiAnalytics.exe

    • Size

      280KB

    • MD5

      73e4408fdaf79d788db02cbdc79b90c0

    • SHA1

      c327a1b6c0f789c425a525d8ea1e7e066ebbc08f

    • SHA256

      32ccf050962266df4e8cec7fdafcfae0f2218c886057654fe0a2e77b18286896

    • SHA512

      8d1db8e4dc43a5ca3feb886c426dff4086c2d36c047ce04a89d7395e90f00de9c195d62ea43ecfe23b19e9be9f62c5c5ad20b50062b171fcbac88c9de457eb15

    • SSDEEP

      3072:Ho/xJw8BsAIm1Yo4hZK7xVG9Btj676ZBI:Ho/xJwIGoqZo4tjS6Y

    Score
    10/10
    • Adds autorun key to be loaded by Explorer.exe on startup

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks