General

  • Target

    357e9c143e4544d3c89579e7dabc45842931bf86e9053643e1548873a000dcda_NeikiAnalytics.exe

  • Size

    66KB

  • Sample

    240701-e5d9yawerf

  • MD5

    d9b129090cfb637566bd5e2c5b0da8f0

  • SHA1

    740b58d57f371bf69f689df0668a782a54ad52e0

  • SHA256

    357e9c143e4544d3c89579e7dabc45842931bf86e9053643e1548873a000dcda

  • SHA512

    588352189ba98e6c0ae4d02d62859904c6f1093510cabd8c0d39e829b243d49ccc70792e19ed46ad21b548384bd25fc60a9e86749e4da6ef06c71c21fe56d408

  • SSDEEP

    768:ZrItKyw5WHXfQIhIiIk9ecAaVPD96KyX63:Zr3Z5IfQIR81ad5yX63

Score
8/10

Malware Config

Targets

    • Target

      357e9c143e4544d3c89579e7dabc45842931bf86e9053643e1548873a000dcda_NeikiAnalytics.exe

    • Size

      66KB

    • MD5

      d9b129090cfb637566bd5e2c5b0da8f0

    • SHA1

      740b58d57f371bf69f689df0668a782a54ad52e0

    • SHA256

      357e9c143e4544d3c89579e7dabc45842931bf86e9053643e1548873a000dcda

    • SHA512

      588352189ba98e6c0ae4d02d62859904c6f1093510cabd8c0d39e829b243d49ccc70792e19ed46ad21b548384bd25fc60a9e86749e4da6ef06c71c21fe56d408

    • SSDEEP

      768:ZrItKyw5WHXfQIhIiIk9ecAaVPD96KyX63:Zr3Z5IfQIR81ad5yX63

    Score
    8/10
    • Sets file to hidden

      Modifies file attributes to stop it showing in Explorer etc.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Deletes itself

    • Executes dropped EXE

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Hide Artifacts

2
T1564

Hidden Files and Directories

2
T1564.001

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks