General

  • Target

    3e5306a59afb06783e4c97fce7bdd35df15bb2706cede9e915c1cb7236fe5684_NeikiAnalytics.exe

  • Size

    72KB

  • Sample

    240701-hvwb9ascjn

  • MD5

    aca5fc0a3560762e601f27d02b874ee0

  • SHA1

    fd08ab80fc8984f95367a4f6d97d24acae3021f4

  • SHA256

    3e5306a59afb06783e4c97fce7bdd35df15bb2706cede9e915c1cb7236fe5684

  • SHA512

    4d0ec106c5625555e7df080dc0075cd5a54034c6bf65b865aaeb2e7b5e1d3204531b420a114f82caa6f8805921cec80aee7c3b0a3cf839ca064ccb0f0e7827d3

  • SSDEEP

    1536:If+z6vL8Wvc/3QTZrLjI5qD266CMb+KR0Nc8QsJq39:Tz6vL8N3CvjI5qa66Ce0Nc8QsC9

Malware Config

Extracted

Family

metasploit

Version

encoder/shikata_ga_nai

Extracted

Family

metasploit

Version

windows/shell_reverse_tcp

C2

161.24.0.80:1234

Targets

    • Target

      3e5306a59afb06783e4c97fce7bdd35df15bb2706cede9e915c1cb7236fe5684_NeikiAnalytics.exe

    • Size

      72KB

    • MD5

      aca5fc0a3560762e601f27d02b874ee0

    • SHA1

      fd08ab80fc8984f95367a4f6d97d24acae3021f4

    • SHA256

      3e5306a59afb06783e4c97fce7bdd35df15bb2706cede9e915c1cb7236fe5684

    • SHA512

      4d0ec106c5625555e7df080dc0075cd5a54034c6bf65b865aaeb2e7b5e1d3204531b420a114f82caa6f8805921cec80aee7c3b0a3cf839ca064ccb0f0e7827d3

    • SSDEEP

      1536:If+z6vL8Wvc/3QTZrLjI5qD266CMb+KR0Nc8QsJq39:Tz6vL8N3CvjI5qa66Ce0Nc8QsC9

    • MetaSploit

      Detected malicious payload which is part of the Metasploit Framework, likely generated with msfvenom or similar.

MITRE ATT&CK Matrix

Tasks