General

  • Target

    38d0137c54277de568a6798e206a1b50624d56660d6f1df4fed3a5ea306b9f30_NeikiAnalytics.exe

  • Size

    648KB

  • Sample

    240701-f52kxa1blk

  • MD5

    0d24b3bfaac195b53449882667afa620

  • SHA1

    4009a9cb833be774dc71593d5bf9eab68d60c453

  • SHA256

    38d0137c54277de568a6798e206a1b50624d56660d6f1df4fed3a5ea306b9f30

  • SHA512

    6acb391a3f4b0f825f18d464a0584050c6dfca7cbccc0ef668af35685ea8094ae2156f3708251df09a88b621d6d3d0784b227560bb9bf4ec28b37c04621e8913

  • SSDEEP

    12288:Iqz2DWUwWCIkeRlk7ugd1EOFcNW2f+zRIxzA0RJ4P3Zu/t4ZJ0FSlg6BdLET7bIV:pz2DWlWHRlMugdD+JsRgZRJ4fM430EgM

Score
7/10

Malware Config

Targets

    • Target

      38d0137c54277de568a6798e206a1b50624d56660d6f1df4fed3a5ea306b9f30_NeikiAnalytics.exe

    • Size

      648KB

    • MD5

      0d24b3bfaac195b53449882667afa620

    • SHA1

      4009a9cb833be774dc71593d5bf9eab68d60c453

    • SHA256

      38d0137c54277de568a6798e206a1b50624d56660d6f1df4fed3a5ea306b9f30

    • SHA512

      6acb391a3f4b0f825f18d464a0584050c6dfca7cbccc0ef668af35685ea8094ae2156f3708251df09a88b621d6d3d0784b227560bb9bf4ec28b37c04621e8913

    • SSDEEP

      12288:Iqz2DWUwWCIkeRlk7ugd1EOFcNW2f+zRIxzA0RJ4P3Zu/t4ZJ0FSlg6BdLET7bIV:pz2DWlWHRlMugdD+JsRgZRJ4fM430EgM

    Score
    7/10
    • Executes dropped EXE

    • Loads dropped DLL

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Credential Access

Unsecured Credentials

1
T1552

Credentials In Files

1
T1552.001

Discovery

System Information Discovery

3
T1082

Query Registry

3
T1012

Peripheral Device Discovery

1
T1120

Collection

Data from Local System

1
T1005

Tasks