General

  • Target

    331af58f254f8544710b5b2ad5f2df4938234c1749a6a53587ad14c6c7898114_NeikiAnalytics.exe

  • Size

    55KB

  • Sample

    240701-ebj84aydlr

  • MD5

    94532c0574e668b9f99b5f872f6d46b0

  • SHA1

    c78c6b18b9a8558a9d4c8a2827570e5a5998e7df

  • SHA256

    331af58f254f8544710b5b2ad5f2df4938234c1749a6a53587ad14c6c7898114

  • SHA512

    9ae69f13c1ae79fd6b6f7fa1b0b21951e511596d06c13563a509b6e553b7312762c6a4cc085f812662c3923c8b3b153a756850d488556ab60548ba24551af493

  • SSDEEP

    768:k8apxj9QN8vzgSa7nM1DUheEvFBkpkIvr9NIgV753JNjVicC7W2W2p/1H5tLXdnh:VaX5zgSazRhRpIvrrIIJN5fuW2W2LDJ

Score
10/10

Malware Config

Targets

    • Target

      331af58f254f8544710b5b2ad5f2df4938234c1749a6a53587ad14c6c7898114_NeikiAnalytics.exe

    • Size

      55KB

    • MD5

      94532c0574e668b9f99b5f872f6d46b0

    • SHA1

      c78c6b18b9a8558a9d4c8a2827570e5a5998e7df

    • SHA256

      331af58f254f8544710b5b2ad5f2df4938234c1749a6a53587ad14c6c7898114

    • SHA512

      9ae69f13c1ae79fd6b6f7fa1b0b21951e511596d06c13563a509b6e553b7312762c6a4cc085f812662c3923c8b3b153a756850d488556ab60548ba24551af493

    • SSDEEP

      768:k8apxj9QN8vzgSa7nM1DUheEvFBkpkIvr9NIgV753JNjVicC7W2W2p/1H5tLXdnh:VaX5zgSazRhRpIvrrIIJN5fuW2W2LDJ

    Score
    10/10
    • Adds autorun key to be loaded by Explorer.exe on startup

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks