Analysis
-
max time kernel
118s -
max time network
120s -
platform
windows7_x64 -
resource
win7-20240419-en -
resource tags
arch:x64arch:x86image:win7-20240419-enlocale:en-usos:windows7-x64system -
submitted
30-06-2024 23:38
Behavioral task
behavioral1
Sample
23b70351e3699335df32f3a06777e2514b8daed6a14c506f5380b6792e0f08e7_NeikiAnalytics.pdf
Resource
win7-20240419-en
Behavioral task
behavioral2
Sample
23b70351e3699335df32f3a06777e2514b8daed6a14c506f5380b6792e0f08e7_NeikiAnalytics.pdf
Resource
win10v2004-20240508-en
General
-
Target
23b70351e3699335df32f3a06777e2514b8daed6a14c506f5380b6792e0f08e7_NeikiAnalytics.pdf
-
Size
75KB
-
MD5
5612f594c1040052b60b9a2940e16b70
-
SHA1
e1f69fd76365b224c7eef715a1a1451daf1514c9
-
SHA256
23b70351e3699335df32f3a06777e2514b8daed6a14c506f5380b6792e0f08e7
-
SHA512
5bdf8f9eef3bb6b6ee926a9d538a962d6fed53fd6881a8719f5a15574791c477a3a278c385975964f0bd9ebe15d1e2e54db7cfa4b7a125d861755893072c86bb
-
SSDEEP
1536:pQluqogjJgSECrR9jWWf6cmUeKc6YGGVBXCGGdW6ojh0W2QUZjJniyPlq/Ox:WluqtECrHSWNeKtY9XDGqfxWZiytfx
Malware Config
Signatures
-
Suspicious behavior: GetForegroundWindowSpam 1 IoCs
Processes:
AcroRd32.exepid process 1680 AcroRd32.exe -
Suspicious use of SetWindowsHookEx 3 IoCs
Processes:
AcroRd32.exepid process 1680 AcroRd32.exe 1680 AcroRd32.exe 1680 AcroRd32.exe
Processes
-
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe"C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe" "C:\Users\Admin\AppData\Local\Temp\23b70351e3699335df32f3a06777e2514b8daed6a14c506f5380b6792e0f08e7_NeikiAnalytics.pdf"1⤵
- Suspicious behavior: GetForegroundWindowSpam
- Suspicious use of SetWindowsHookEx
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Users\Admin\AppData\Roaming\Adobe\Acrobat\9.0\SharedDataEventsFilesize
3KB
MD5c0c6a9ba24a10a902f73e763e3fda3dc
SHA12aa24dc66ca3b702520c684b836f291c258eef15
SHA2564723799ffa596e42c052369892689093282faad521abfd3f779829f1729456cb
SHA512d641073776dca2220d6dc0a35c1568dcf8ab70372b23f216457cd686a9c3debe1d396d3a31d82aa7258874466789abf77b190990a1144c52992fdd68cffbb035