General

  • Target

    349738d8807566344fb0deafa27c2ed9a72662024368563a9c3b019f0d923b9d_NeikiAnalytics.exe

  • Size

    109KB

  • Sample

    240701-et5bzswclh

  • MD5

    1f42ba740cf1a9850714e912e2d46890

  • SHA1

    bc9ebe0772cc8ed2923c72e4fd2b1401ea8664bc

  • SHA256

    349738d8807566344fb0deafa27c2ed9a72662024368563a9c3b019f0d923b9d

  • SHA512

    c427e61e376255290c20ed594d3a5ea3811e48378b52f94bf505bae3e3cbae0067a0ad4441d20744b2ab26d5f959ba3bf5d6aacc871a600b0c9dcb065f4fd214

  • SSDEEP

    3072:gMzHLyEyF1hpRcLfMZ7h28fo3PXl9Z7S/yCsKh2EzZA/z:gMvEF3p0fMZ7h2go35e/yCthvUz

Score
10/10

Malware Config

Targets

    • Target

      349738d8807566344fb0deafa27c2ed9a72662024368563a9c3b019f0d923b9d_NeikiAnalytics.exe

    • Size

      109KB

    • MD5

      1f42ba740cf1a9850714e912e2d46890

    • SHA1

      bc9ebe0772cc8ed2923c72e4fd2b1401ea8664bc

    • SHA256

      349738d8807566344fb0deafa27c2ed9a72662024368563a9c3b019f0d923b9d

    • SHA512

      c427e61e376255290c20ed594d3a5ea3811e48378b52f94bf505bae3e3cbae0067a0ad4441d20744b2ab26d5f959ba3bf5d6aacc871a600b0c9dcb065f4fd214

    • SSDEEP

      3072:gMzHLyEyF1hpRcLfMZ7h28fo3PXl9Z7S/yCsKh2EzZA/z:gMvEF3p0fMZ7h2go35e/yCthvUz

    Score
    10/10
    • Adds autorun key to be loaded by Explorer.exe on startup

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks