General

  • Target

    2ffb69094d747ebe84ec03987a154649ba0b1d0bd1a576fcc65330bc6f4db0b2_NeikiAnalytics.exe

  • Size

    2.0MB

  • Sample

    240702-eac4dstgke

  • MD5

    b59155dd3316809361b0eb816a7c9250

  • SHA1

    fa824a4fe02018742ef9dbfd50a6bab455280df6

  • SHA256

    2ffb69094d747ebe84ec03987a154649ba0b1d0bd1a576fcc65330bc6f4db0b2

  • SHA512

    3ec66351293dc6d2accefa2e06c549cdf612d42df4bba38ab857fcf00609b6c8010d16568ab21131faa93419e54b541810ecc808f0fdbda984a11ca5bace8b25

  • SSDEEP

    49152:BezaTF8FcNkNdfE0pZ9ozt4wIC5aIwC+Agr6KI3h:BemTLkNdfE0pZrwZ

Malware Config

Targets

    • Target

      2ffb69094d747ebe84ec03987a154649ba0b1d0bd1a576fcc65330bc6f4db0b2_NeikiAnalytics.exe

    • Size

      2.0MB

    • MD5

      b59155dd3316809361b0eb816a7c9250

    • SHA1

      fa824a4fe02018742ef9dbfd50a6bab455280df6

    • SHA256

      2ffb69094d747ebe84ec03987a154649ba0b1d0bd1a576fcc65330bc6f4db0b2

    • SHA512

      3ec66351293dc6d2accefa2e06c549cdf612d42df4bba38ab857fcf00609b6c8010d16568ab21131faa93419e54b541810ecc808f0fdbda984a11ca5bace8b25

    • SSDEEP

      49152:BezaTF8FcNkNdfE0pZ9ozt4wIC5aIwC+Agr6KI3h:BemTLkNdfE0pZrwZ

    • KPOT

      KPOT is an information stealer that steals user data and account credentials.

    • KPOT Core Executable

    • xmrig

      XMRig is a high performance, open source, cross platform CPU/GPU miner.

    • XMRig Miner payload

    • Executes dropped EXE

    • Loads dropped DLL

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks