General

  • Target

    3b964e119fa130a5868846adc2e2bc15c7aed5967ca87c9b472ad0d40bae4f74_NeikiAnalytics.exe

  • Size

    2.0MB

  • Sample

    240701-g39n6sxhre

  • MD5

    4a4ad534f52f22b9a564989cc89f2bf0

  • SHA1

    07c00a97f06f1776965a64a284e8dbda377da6c9

  • SHA256

    3b964e119fa130a5868846adc2e2bc15c7aed5967ca87c9b472ad0d40bae4f74

  • SHA512

    d83f9b1cc09268d61ceeb19b22dd16b915461d15ecedaef99bfd6e727e1daa4e5ef08ad92226ff94febf189db973dfcfe02591753d787b75310393a315501a84

  • SSDEEP

    24576:zt6/EQTelL3j9Uvbq7Frn/WVZQC3qOazxjodGjeNittkpAVRTZIjDPG3ib3tuuXJ:z/Uvbq7UoC3gxVtIAV+RZuuJa0

Malware Config

Targets

    • Target

      3b964e119fa130a5868846adc2e2bc15c7aed5967ca87c9b472ad0d40bae4f74_NeikiAnalytics.exe

    • Size

      2.0MB

    • MD5

      4a4ad534f52f22b9a564989cc89f2bf0

    • SHA1

      07c00a97f06f1776965a64a284e8dbda377da6c9

    • SHA256

      3b964e119fa130a5868846adc2e2bc15c7aed5967ca87c9b472ad0d40bae4f74

    • SHA512

      d83f9b1cc09268d61ceeb19b22dd16b915461d15ecedaef99bfd6e727e1daa4e5ef08ad92226ff94febf189db973dfcfe02591753d787b75310393a315501a84

    • SSDEEP

      24576:zt6/EQTelL3j9Uvbq7Frn/WVZQC3qOazxjodGjeNittkpAVRTZIjDPG3ib3tuuXJ:z/Uvbq7UoC3gxVtIAV+RZuuJa0

    • Executes dropped EXE

    • Loads dropped DLL

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

    • Writes to the Master Boot Record (MBR)

      Bootkits write to the MBR to gain persistence at a level below the operating system.

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Defense Evasion

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Tasks