General

  • Target

    34f7260a054737d8dc2eef2efda50bcc1dad22cb91e7e0139d4ef1086636d225_NeikiAnalytics.exe

  • Size

    320KB

  • Sample

    240701-ey4k9azalm

  • MD5

    a2de5adec5d31797c142436561af28e0

  • SHA1

    c38354e652c9a1ff8c1bda652656859fa6458e66

  • SHA256

    34f7260a054737d8dc2eef2efda50bcc1dad22cb91e7e0139d4ef1086636d225

  • SHA512

    ddacbe2f7a74b62cf0d9210b45ecef9420bfaf2d669f2023a8c32034ab2afc5b2c01fb92e36316089b16ddc3da5bc06cc7f92e0600a09c02eeb1cab8036f8cc4

  • SSDEEP

    3072:nuEBi+VOoze1y8/41QUUZm8/41QrAoUZ4pWLB51jozFWLBggS2LHqN:uNOOuevZgZ0Wd/OWdPS2L8

Score
10/10

Malware Config

Targets

    • Target

      34f7260a054737d8dc2eef2efda50bcc1dad22cb91e7e0139d4ef1086636d225_NeikiAnalytics.exe

    • Size

      320KB

    • MD5

      a2de5adec5d31797c142436561af28e0

    • SHA1

      c38354e652c9a1ff8c1bda652656859fa6458e66

    • SHA256

      34f7260a054737d8dc2eef2efda50bcc1dad22cb91e7e0139d4ef1086636d225

    • SHA512

      ddacbe2f7a74b62cf0d9210b45ecef9420bfaf2d669f2023a8c32034ab2afc5b2c01fb92e36316089b16ddc3da5bc06cc7f92e0600a09c02eeb1cab8036f8cc4

    • SSDEEP

      3072:nuEBi+VOoze1y8/41QUUZm8/41QrAoUZ4pWLB51jozFWLBggS2LHqN:uNOOuevZgZ0Wd/OWdPS2L8

    Score
    10/10
    • Adds autorun key to be loaded by Explorer.exe on startup

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks