Analysis
-
max time kernel
119s -
max time network
121s -
platform
windows7_x64 -
resource
win7-20240611-en -
resource tags
arch:x64arch:x86image:win7-20240611-enlocale:en-usos:windows7-x64system -
submitted
29-06-2024 17:46
Behavioral task
behavioral1
Sample
b5aae659556f00ccbaf574170bbd5450a804cf146943de3ace3703f7e0960fd7_NeikiAnalytics.pdf
Resource
win7-20240611-en
Behavioral task
behavioral2
Sample
b5aae659556f00ccbaf574170bbd5450a804cf146943de3ace3703f7e0960fd7_NeikiAnalytics.pdf
Resource
win10v2004-20240226-en
General
-
Target
b5aae659556f00ccbaf574170bbd5450a804cf146943de3ace3703f7e0960fd7_NeikiAnalytics.pdf
-
Size
11KB
-
MD5
540519c24fd00643e52a8ed2cf9639e0
-
SHA1
8989c6f841063bf028bdb0e91da9f2f1daa977ab
-
SHA256
b5aae659556f00ccbaf574170bbd5450a804cf146943de3ace3703f7e0960fd7
-
SHA512
8450b06683d989110d2eb05cf4b8bb83e4e6499898b65717741fd78753a3be55f2d48db2b10e9c57dacb318511da2ca59f2ea4a78006e578c15d5a1bf7e2736e
-
SSDEEP
192:e2FUKhD0Q4FY8Kn+lxwHRkB7HXTMA08TAggUiNxzUurpVgdTt2n2VLGn3w15C:eO4a8s+4RkB7HAANp3YVfgTRk3w15C
Malware Config
Signatures
-
Suspicious behavior: GetForegroundWindowSpam 1 IoCs
Processes:
AcroRd32.exepid process 2620 AcroRd32.exe -
Suspicious use of SetWindowsHookEx 3 IoCs
Processes:
AcroRd32.exepid process 2620 AcroRd32.exe 2620 AcroRd32.exe 2620 AcroRd32.exe
Processes
-
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe"C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe" "C:\Users\Admin\AppData\Local\Temp\b5aae659556f00ccbaf574170bbd5450a804cf146943de3ace3703f7e0960fd7_NeikiAnalytics.pdf"1⤵
- Suspicious behavior: GetForegroundWindowSpam
- Suspicious use of SetWindowsHookEx
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Users\Admin\AppData\Roaming\Adobe\Acrobat\9.0\SharedDataEventsFilesize
3KB
MD565ef93f48215452e8fcbffc3df052f2f
SHA122404cadaa972e188c88faf0b3484486c611ff3e
SHA256f7721858c81fa756f2cdb38a9e1f263365b902d2cd25e5fe6d1b0ca4079d593f
SHA51287adb7ef87de22f81b1340bccef6f90f1490ff0874d6b1d7fdddfcc5688fdeb0b5968e6f4e2d219853335cc1fc3845fa1421a64f89faf38c3635f8fe43813377