General

  • Target

    35296da639d6f1a235f31b6972c26814d55812ca3045949e0de5831926dc50fa_NeikiAnalytics.exe

  • Size

    1.6MB

  • Sample

    240701-e2nzzazbkj

  • MD5

    b3c39b60c98ec19c10d0be758fc02e00

  • SHA1

    35afe28c261662f611a6efa1b5cd5dce4171d8b1

  • SHA256

    35296da639d6f1a235f31b6972c26814d55812ca3045949e0de5831926dc50fa

  • SHA512

    532557f58efcbc83c78178958d52fbf64bc60c0cd135bbab938058d34ec58aa056e3079279b959b4e2a3dd022d7989c0fb1417d5e0ecf02a092e3e7538d3134f

  • SSDEEP

    24576:JanwhSe11QSONCpGJCjETPlGC78XIHbAYhbc8lFad+tszICTW0hm3+Pa4202:knw9oUUEEDlGUJ8Y9c87Medl

Malware Config

Targets

    • Target

      35296da639d6f1a235f31b6972c26814d55812ca3045949e0de5831926dc50fa_NeikiAnalytics.exe

    • Size

      1.6MB

    • MD5

      b3c39b60c98ec19c10d0be758fc02e00

    • SHA1

      35afe28c261662f611a6efa1b5cd5dce4171d8b1

    • SHA256

      35296da639d6f1a235f31b6972c26814d55812ca3045949e0de5831926dc50fa

    • SHA512

      532557f58efcbc83c78178958d52fbf64bc60c0cd135bbab938058d34ec58aa056e3079279b959b4e2a3dd022d7989c0fb1417d5e0ecf02a092e3e7538d3134f

    • SSDEEP

      24576:JanwhSe11QSONCpGJCjETPlGC78XIHbAYhbc8lFad+tszICTW0hm3+Pa4202:knw9oUUEEDlGUJ8Y9c87Medl

    • xmrig

      XMRig is a high performance, open source, cross platform CPU/GPU miner.

    • XMRig Miner payload

    • Executes dropped EXE

    • Loads dropped DLL

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Event Triggered Execution

1
T1546

Accessibility Features

1
T1546.008

Privilege Escalation

Event Triggered Execution

1
T1546

Accessibility Features

1
T1546.008

Tasks