Static task
static1
Behavioral task
behavioral1
Sample
1e27eaa8329b64a88a214d7d68f0943c354bc402edfb76ed4a44b306c54e4aad_NeikiAnalytics.exe
Resource
win7-20240220-en
General
-
Target
1e27eaa8329b64a88a214d7d68f0943c354bc402edfb76ed4a44b306c54e4aad_NeikiAnalytics.exe
-
Size
3.1MB
-
MD5
6616eefb59184e80deea3d8e3d91a970
-
SHA1
6bf289094c5ea6a4e478ca61a6f92ab5d534b31e
-
SHA256
1e27eaa8329b64a88a214d7d68f0943c354bc402edfb76ed4a44b306c54e4aad
-
SHA512
a53b8a32bda43ff9c052957ef1d980f3cf83b7d4eb68cf2f3e2c8f3a0c32dfcdd0a3b36411af3afb38ef94c685d67e096d6dc09ac1cb29e4491ec21d0142e5f9
-
SSDEEP
49152:wjJ/b1Upgw5j7nM7a5tKqsevboS8/pd9I+gdgDB2WcCNRvJmbCW8wiKUhdcF6cCv:JnM+Z0S8/po+g2VNRRmbCd1O6cjS0q
Malware Config
Signatures
-
Unsigned PE 1 IoCs
Checks for missing Authenticode signature.
Processes:
resource 1e27eaa8329b64a88a214d7d68f0943c354bc402edfb76ed4a44b306c54e4aad_NeikiAnalytics.exe
Files
-
1e27eaa8329b64a88a214d7d68f0943c354bc402edfb76ed4a44b306c54e4aad_NeikiAnalytics.exe.exe windows:4 windows x64 arch:x64
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
Sections
>N`4 Size: 298KB - Virtual size: 298KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
>N`4 Size: 298KB - Virtual size: 298KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.text Size: 2.5MB - Virtual size: 2.5MB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rsrc Size: 1KB - Virtual size: 1KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
eDejtZqN Size: 512B - Virtual size: 22B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.???? Size: 512B - Virtual size: 276B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ