Analysis
-
max time kernel
121s -
max time network
121s -
platform
windows7_x64 -
resource
win7-20240419-en -
resource tags
arch:x64arch:x86image:win7-20240419-enlocale:en-usos:windows7-x64system -
submitted
29-06-2024 17:01
Behavioral task
behavioral1
Sample
b42a80a37f89df92e967cb8dea89edab7fb7f7e466ed30af51fc4bd35563f539_NeikiAnalytics.pdf
Resource
win7-20240419-en
Behavioral task
behavioral2
Sample
b42a80a37f89df92e967cb8dea89edab7fb7f7e466ed30af51fc4bd35563f539_NeikiAnalytics.pdf
Resource
win10v2004-20240508-en
General
-
Target
b42a80a37f89df92e967cb8dea89edab7fb7f7e466ed30af51fc4bd35563f539_NeikiAnalytics.pdf
-
Size
200KB
-
MD5
419ae6de7b8091a280a99c25332b88e0
-
SHA1
6f4cb1002a2461aee55f91cca90445b1482a26be
-
SHA256
b42a80a37f89df92e967cb8dea89edab7fb7f7e466ed30af51fc4bd35563f539
-
SHA512
bd83fe16f41aefaafc1596f9fb28b84d6f59de37d80d27c492e58540cdaf238535ba3aac25bff34894dd87a70637fc79651beda8335a5898b30cb50147017e2f
-
SSDEEP
6144:iHQ1oj+B+pPGjwhISfLCSBHjnaXdWAuc76:Xoj+BQPGOGSZHAP6
Malware Config
Signatures
-
Suspicious behavior: GetForegroundWindowSpam 1 IoCs
Processes:
AcroRd32.exepid process 1992 AcroRd32.exe -
Suspicious use of SetWindowsHookEx 4 IoCs
Processes:
AcroRd32.exepid process 1992 AcroRd32.exe 1992 AcroRd32.exe 1992 AcroRd32.exe 1992 AcroRd32.exe
Processes
-
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe"C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe" "C:\Users\Admin\AppData\Local\Temp\b42a80a37f89df92e967cb8dea89edab7fb7f7e466ed30af51fc4bd35563f539_NeikiAnalytics.pdf"1⤵
- Suspicious behavior: GetForegroundWindowSpam
- Suspicious use of SetWindowsHookEx
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Users\Admin\AppData\Roaming\Adobe\Acrobat\9.0\SharedDataEventsFilesize
3KB
MD596ebbee20f127d301d2285e816458f36
SHA1a49015b101b5792d715539b33d025f5535465fc6
SHA256bfef72f3e0c7a9332a88296fd3b1678883de5a7702b62a563185fbc4e5adbc81
SHA512c73ac366c38f0cbdaaeabc5c73661378197ddc2a23b24be83cc18d74f2c7e9498f163384c07547eb0dee4287d2e022ec3e14ef181b8741d147c0a0eb1413b428