General

  • Target

    3494af4f6f0e306d3f2431945e86f5e85dd6d48d0f8735860a57e1f03409b660_NeikiAnalytics.exe

  • Size

    52KB

  • Sample

    240701-ety5zawcld

  • MD5

    59ea2c4b6f74be6ec18f5cefe20caf40

  • SHA1

    ce7192ce33c17ddd20231a52f66ebd6005a8db5a

  • SHA256

    3494af4f6f0e306d3f2431945e86f5e85dd6d48d0f8735860a57e1f03409b660

  • SHA512

    c8f2d1b977f83d99592a70f5b79c747b28f4bb571c1255fe14d118cc351e173d82622eb53c9234c3671f8d14318ad42a6c5d05748a174fe35d6a2e321915f7dc

  • SSDEEP

    768:k/Y3uesKNTg6N6qADKPBWyDLB5cLHVkZvUphcf8s/1H5F/sTMABvKWe:F3uesKxMDEBWy3BqjVWC7iWMAdKZ

Score
10/10

Malware Config

Targets

    • Target

      3494af4f6f0e306d3f2431945e86f5e85dd6d48d0f8735860a57e1f03409b660_NeikiAnalytics.exe

    • Size

      52KB

    • MD5

      59ea2c4b6f74be6ec18f5cefe20caf40

    • SHA1

      ce7192ce33c17ddd20231a52f66ebd6005a8db5a

    • SHA256

      3494af4f6f0e306d3f2431945e86f5e85dd6d48d0f8735860a57e1f03409b660

    • SHA512

      c8f2d1b977f83d99592a70f5b79c747b28f4bb571c1255fe14d118cc351e173d82622eb53c9234c3671f8d14318ad42a6c5d05748a174fe35d6a2e321915f7dc

    • SSDEEP

      768:k/Y3uesKNTg6N6qADKPBWyDLB5cLHVkZvUphcf8s/1H5F/sTMABvKWe:F3uesKxMDEBWy3BqjVWC7iWMAdKZ

    Score
    10/10
    • Adds autorun key to be loaded by Explorer.exe on startup

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks