General

  • Target

    380825786038c6d7d7a99130b2215bb9ec3729cba29d94e8a1b0e9fae82db1d7_NeikiAnalytics.exe

  • Size

    2.0MB

  • Sample

    240701-fw642axcle

  • MD5

    dc767e0fa485caff5a97465dfbde66e0

  • SHA1

    4404660668ffd1c6424cb9d793b7b229f1f95e83

  • SHA256

    380825786038c6d7d7a99130b2215bb9ec3729cba29d94e8a1b0e9fae82db1d7

  • SHA512

    46acc09cf6ea3d71dbfcfdddc84c2cea3d36e0f905ce010b953691543200830ce909edf5a8ed45564fb2d7301f64786e29e3e64912a702066ad1d7962bb72bd3

  • SSDEEP

    49152:BezaTF8FcNkNdfE0pZ9ozt4wIC5aIwC+Agr6KI3aO:BemTLkNdfE0pZrwF

Malware Config

Targets

    • Target

      380825786038c6d7d7a99130b2215bb9ec3729cba29d94e8a1b0e9fae82db1d7_NeikiAnalytics.exe

    • Size

      2.0MB

    • MD5

      dc767e0fa485caff5a97465dfbde66e0

    • SHA1

      4404660668ffd1c6424cb9d793b7b229f1f95e83

    • SHA256

      380825786038c6d7d7a99130b2215bb9ec3729cba29d94e8a1b0e9fae82db1d7

    • SHA512

      46acc09cf6ea3d71dbfcfdddc84c2cea3d36e0f905ce010b953691543200830ce909edf5a8ed45564fb2d7301f64786e29e3e64912a702066ad1d7962bb72bd3

    • SSDEEP

      49152:BezaTF8FcNkNdfE0pZ9ozt4wIC5aIwC+Agr6KI3aO:BemTLkNdfE0pZrwF

    • KPOT

      KPOT is an information stealer that steals user data and account credentials.

    • KPOT Core Executable

    • xmrig

      XMRig is a high performance, open source, cross platform CPU/GPU miner.

    • XMRig Miner payload

    • Executes dropped EXE

    • Loads dropped DLL

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks