General

  • Target

    7ad39bfaf9ce17c54262523ec8c76e597f870b29226f40a10f8d4df03c308d4d_NeikiAnalytics.exe

  • Size

    733KB

  • MD5

    0a1ad78b7445d452a8b9e30cc96f3e20

  • SHA1

    0fb048733f46346a769a32a367e1d9341856899c

  • SHA256

    7ad39bfaf9ce17c54262523ec8c76e597f870b29226f40a10f8d4df03c308d4d

  • SHA512

    991be91a3a4eb44d31bc6f6cf638ee29aee42e8ea470b5ce546e63689f8cf874c377850239986b8f575ce947704028a6e2855c68c5726d8ccf9b7e5b974ffd08

  • SSDEEP

    12288:baxvpA0aa6nJ6Jl3+4tdqoeBcVgaOZi85uGgGn47nX6SoJb0CbPcgIsHwrdU68qO:baQBnJgl3+42BcVtOZiDPG6KSm4CrcX8

Score
3/10

Malware Config

Signatures

  • One or more HTTP URLs in PDF identified

    Detects presence of HTTP links in PDF files.

  • Unsigned PE 7 IoCs

    Checks for missing Authenticode signature.

  • NSIS installer 1 IoCs

Files

  • 7ad39bfaf9ce17c54262523ec8c76e597f870b29226f40a10f8d4df03c308d4d_NeikiAnalytics.exe
    .exe windows:4 windows x86 arch:x86

    18bc6fa81e19f21156316b1ae696ed6b


    Headers

    Imports

    Sections

  • $PLUGINSDIR/InstallOptions.dll
    .dll windows:4 windows x86 arch:x86

    57354bdeea3dfae6e948101add87501a


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/StartMenu.dll
    .dll windows:4 windows x86 arch:x86

    28d94e5199b88ad374b3cb2118e31a66


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/System.dll
    .dll windows:4 windows x86 arch:x86

    4ec328f99bdd944fc98d8a5cf11f7a62


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/UserInfo.dll
    .dll windows:4 windows x86 arch:x86

    48cfa0ea7e353e4a7dd23572da8374ef


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/ioSpecial.ini
  • $PLUGINSDIR/modern-wizard.bmp
  • CSBuilder/BIOSData/MemAcc.cs
  • CSBuilder/Map/MemAcc.cs
  • CSBuilder/MemTest/MemAcc.cs
  • CSBuilder/PCI/MemAcc.cs
  • Delphi.NET/BIOSData/Zeal.MemAcc.pas
    .js
  • Delphi.NET/Map/Zeal.MemAcc.pas
    .js
  • Delphi.NET/MemTest/Zeal.MemAcc.pas
    .js
  • Delphi.NET/PCI/Zeal.MemAcc.pas
    .js
  • LICENSE.TXT
  • MemAcc.bas
    .vbs
  • MemAcc.chm
    .chm
  • MemAcc.cs
  • MemAcc.lib
  • MemAcc.pas
    .js
  • MemAcc.pdf
    .pdf
    • http://Library43www.zealsoftstudio.com

    • http://Librarywww.zealsoftstudio.com

    • http://O.by

    • http://memacc.inc

    • http://public.bta.net.cn

    • http://www.checklistbox.com

    • http://www.microsoft.com/directx

    • http://www.zealsoft.com/upgrade/

    • http://www.zealsoftstudio.com

    • Show all
  • MemAcc.vb
    .vbs
  • Memacc.h
  • ReadMe.txt
  • Redist/MEMACC.VXD
  • Redist/MemAcc.sys
    .sys windows:5 windows x86 arch:x86

    fc5f24dd874081086a8803550256a943


    Headers

    Imports

    Sections

  • Redist/memacc.reg
  • Redist/memaccvb6.reg
  • Redist/x64/$R0
    .sys windows:5 windows x86 arch:x86

    fc5f24dd874081086a8803550256a943


    Headers

    Imports

    Sections

  • Redist/x64/$SYSDIR/MemAcc.vxd
  • VB.NET/BIOSData/MemAcc.vb
    .vbs
  • VB.NET/Map/MemAcc.vb
    .vbs
  • VB.NET/MemTest/MemAcc.vb
    .vbs
  • VB.NET/PCI/MemAcc.vb
    .vbs
  • VCSharp/BIOSData/MemAcc.cs
  • VCSharp/Map/MemAcc.cs
  • VCSharp/MemTest/MemAcc.cs
  • VCSharp/PCI/MemAcc.cs
  • Zeal.MemAcc.pas
    .js
  • bcbmem.lib