General

  • Target

    330e76e405dd48927cdbae733fe7ff27054437f2f7304942ead6a79bd3a2cb79_NeikiAnalytics.exe

  • Size

    324KB

  • Sample

    240701-eayp4aydkp

  • MD5

    a65744409060e3a97a6483b024873620

  • SHA1

    1d3a5c79900610a3db97c0c854f6cb9eca70ba5a

  • SHA256

    330e76e405dd48927cdbae733fe7ff27054437f2f7304942ead6a79bd3a2cb79

  • SHA512

    50d8dd156b9090061eb92b2cbcba7d937d5a88728197144354d1df9ff6f0b297177a5cb2278e6b2a23249dc3269e1836ee5025eaebb7e4f2349d61fcf3e2047f

  • SSDEEP

    6144:A//ICMmDRxs3NBR+Gu5QTfDTwLvZeDkFXa10gG5kwJZnL8Xg0N8k2+4x:A//vi9BbTvwrZm0gGSQggw8dT

Malware Config

Targets

    • Target

      330e76e405dd48927cdbae733fe7ff27054437f2f7304942ead6a79bd3a2cb79_NeikiAnalytics.exe

    • Size

      324KB

    • MD5

      a65744409060e3a97a6483b024873620

    • SHA1

      1d3a5c79900610a3db97c0c854f6cb9eca70ba5a

    • SHA256

      330e76e405dd48927cdbae733fe7ff27054437f2f7304942ead6a79bd3a2cb79

    • SHA512

      50d8dd156b9090061eb92b2cbcba7d937d5a88728197144354d1df9ff6f0b297177a5cb2278e6b2a23249dc3269e1836ee5025eaebb7e4f2349d61fcf3e2047f

    • SSDEEP

      6144:A//ICMmDRxs3NBR+Gu5QTfDTwLvZeDkFXa10gG5kwJZnL8Xg0N8k2+4x:A//vi9BbTvwrZm0gGSQggw8dT

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Adds Run key to start application

    • Enumerates connected drives

      Attempts to read the root path of hard drives other than the default C: drive.

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Credential Access

Unsecured Credentials

1
T1552

Credentials In Files

1
T1552.001

Discovery

Query Registry

1
T1012

Peripheral Device Discovery

1
T1120

System Information Discovery

2
T1082

Collection

Data from Local System

1
T1005

Tasks