General

  • Target

    31de19123fa3024affc52f2e5c6d5b2eb29a4f8dd64c1a7fae4284d64aaa7a38_NeikiAnalytics.exe

  • Size

    2.0MB

  • Sample

    240701-dygwtayanm

  • MD5

    12fe666b7e791621df6efff05516a400

  • SHA1

    08568106cbda656277be10237777ae3ef39aa9aa

  • SHA256

    31de19123fa3024affc52f2e5c6d5b2eb29a4f8dd64c1a7fae4284d64aaa7a38

  • SHA512

    073b09cec4e1e2728ba5dd4f5441dc96dcb4d85695d4c9bd60465fd7a59802125e00467b41991e559c85ec72b8aaa31255234de4085636048e32c0e500988916

  • SSDEEP

    49152:BezaTF8FcNkNdfE0pZ9ozt4wIXIZbINXe6GcFsA:BemTLkNdfE0pZrf

Malware Config

Targets

    • Target

      31de19123fa3024affc52f2e5c6d5b2eb29a4f8dd64c1a7fae4284d64aaa7a38_NeikiAnalytics.exe

    • Size

      2.0MB

    • MD5

      12fe666b7e791621df6efff05516a400

    • SHA1

      08568106cbda656277be10237777ae3ef39aa9aa

    • SHA256

      31de19123fa3024affc52f2e5c6d5b2eb29a4f8dd64c1a7fae4284d64aaa7a38

    • SHA512

      073b09cec4e1e2728ba5dd4f5441dc96dcb4d85695d4c9bd60465fd7a59802125e00467b41991e559c85ec72b8aaa31255234de4085636048e32c0e500988916

    • SSDEEP

      49152:BezaTF8FcNkNdfE0pZ9ozt4wIXIZbINXe6GcFsA:BemTLkNdfE0pZrf

    • xmrig

      XMRig is a high performance, open source, cross platform CPU/GPU miner.

    • XMRig Miner payload

    • Executes dropped EXE

    • Loads dropped DLL

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Event Triggered Execution

1
T1546

Accessibility Features

1
T1546.008

Privilege Escalation

Event Triggered Execution

1
T1546

Accessibility Features

1
T1546.008

Tasks