d:\hd_audio\dell_cpl\rtdcpl\release\RtDCpl.pdb
Static task
static1
Behavioral task
behavioral1
Sample
0c5431c5e96cc8d4bebee62ac18b5148cf258d24110df0234369d1120f59e837_NeikiAnalytics.exe
Resource
win7-20240508-en
General
-
Target
0c5431c5e96cc8d4bebee62ac18b5148cf258d24110df0234369d1120f59e837_NeikiAnalytics.exe
-
Size
2.6MB
-
MD5
b49dc8f69ac23f4bf4e622838f261090
-
SHA1
e99f32777841e4690f48c1bb6fc577cf2c6facdb
-
SHA256
0c5431c5e96cc8d4bebee62ac18b5148cf258d24110df0234369d1120f59e837
-
SHA512
3bdb7169ba9e7c1b3f88968c46edd344d8fe41b617e59a2e093fd442d8c2b1d6340a8cb468ec98cabfa42ca5475daac99b9b70c1537269045c683ed92e1a2cf6
-
SSDEEP
49152:J47nAkqv4U8T1eVVJmw6ckeswR1Dlif5k5:+nAkVU8T1eVxkORfu5k5
Malware Config
Signatures
-
Unsigned PE 1 IoCs
Checks for missing Authenticode signature.
Processes:
resource 0c5431c5e96cc8d4bebee62ac18b5148cf258d24110df0234369d1120f59e837_NeikiAnalytics.exe
Files
-
0c5431c5e96cc8d4bebee62ac18b5148cf258d24110df0234369d1120f59e837_NeikiAnalytics.exe.exe windows:4 windows x86 arch:x86
29873d15370ee0c74276bb747c4f63ec
Headers
File Characteristics
IMAGE_FILE_RELOCS_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_32BIT_MACHINE
PDB Paths
Imports
setupapi
SetupDiGetDeviceInstanceIdW
SetupDiGetDeviceRegistryPropertyW
SetupDiDestroyDeviceInfoList
SetupDiGetDeviceInterfaceDetailW
SetupDiEnumDeviceInterfaces
SetupDiEnumDeviceInfo
SetupDiGetClassDevsW
winmm
mixerOpen
mixerClose
mixerGetLineInfoW
mixerGetLineControlsW
mixerGetControlDetailsW
mixerSetControlDetails
mixerGetNumDevs
mixerGetDevCapsW
gdiplus
GdipGetImagePixelFormat
GdipSetInterpolationMode
GdipDrawImageRectI
GdiplusStartup
GdipCreateBitmapFromStream
GdipDrawImageI
GdipGetImageGraphicsContext
GdipCreateBitmapFromScan0
GdipAlloc
GdipBitmapUnlockBits
GdipBitmapLockBits
GdipGetImagePalette
GdipDisposeImage
GdipGetImagePaletteSize
GdipCloneImage
GdipDeleteGraphics
GdipGetImageWidth
GdipFree
GdiplusShutdown
GdipCreateFromHDC
GdipCreateBitmapFromHBITMAP
GdipGetImageHeight
kernel32
InterlockedDecrement
CompareStringA
LoadLibraryExW
GetLocaleInfoW
EnumResourceLanguagesW
GetVersion
ConvertDefaultLocale
GetCurrentThread
GetSystemDirectoryW
GetCurrentProcessId
GetThreadLocale
FileTimeToSystemTime
InterlockedIncrement
TlsGetValue
GlobalReAlloc
GlobalHandle
TlsAlloc
TlsSetValue
LocalReAlloc
TlsFree
GlobalFlags
ReadFile
WriteFile
SetFilePointer
FlushFileBuffers
LockFile
GetModuleFileNameW
SetEndOfFile
GetFileSize
FindClose
FindFirstFileW
GetVolumeInformationW
GetFullPathNameW
SetErrorMode
FileTimeToLocalFileTime
GetFileAttributesW
GetFileTime
GetTickCount
HeapFree
HeapAlloc
GetProcessHeap
GetStartupInfoW
VirtualProtect
VirtualAlloc
GetSystemInfo
VirtualQuery
RtlUnwind
HeapReAlloc
ExitThread
ExitProcess
HeapSize
SetUnhandledExceptionFilter
GetStdHandle
GetModuleFileNameA
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineA
GetCommandLineW
SetHandleCount
GetFileType
GetStartupInfoA
HeapDestroy
HeapCreate
VirtualFree
QueryPerformanceCounter
GetSystemTimeAsFileTime
TerminateProcess
UnhandledExceptionFilter
IsDebuggerPresent
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
LCMapStringA
LCMapStringW
GetTimeZoneInformation
GetStringTypeA
GetStringTypeW
GetLocaleInfoA
GetConsoleCP
GetConsoleMode
SetStdHandle
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
CreateFileA
SetEnvironmentVariableA
GetModuleHandleA
SuspendThread
SetThreadPriority
lstrlenA
lstrcmpA
WritePrivateProfileStringW
GetPrivateProfileIntW
FreeResource
GlobalAddAtomW
GlobalFindAtomW
GlobalDeleteAtom
LoadLibraryW
CompareStringW
lstrcmpW
GetModuleHandleW
GetVersionExA
SetLastError
FormatMessageW
MulDiv
WideCharToMultiByte
RaiseException
LoadLibraryA
FreeLibrary
GetProcAddress
CreateMutexW
MultiByteToWideChar
FindResourceExW
GetUserDefaultUILanguage
LocalAlloc
LocalFree
GlobalFree
GlobalUnlock
GlobalLock
GlobalAlloc
CreateThread
InterlockedExchange
GetCurrentThreadId
GetLastError
DeviceIoControl
CreateFileW
ResumeThread
GetCurrentProcess
DuplicateHandle
lstrlenW
CreateEventW
InitializeCriticalSection
GetVersionExW
LeaveCriticalSection
Sleep
WaitForMultipleObjects
DeleteCriticalSection
CloseHandle
EnterCriticalSection
WaitForSingleObject
GetExitCodeThread
SetEvent
LoadResource
LockResource
SizeofResource
FindResourceW
UnlockFile
user32
ValidateRect
GetCursorPos
GetActiveWindow
GetMessageW
FillRect
TabbedTextOutW
DrawTextExW
GrayStringW
ClientToScreen
GetDC
ReleaseDC
GetWindowDC
BeginPaint
EndPaint
EndDialog
GetNextDlgTabItem
CreateDialogIndirectParamW
WindowFromPoint
DestroyMenu
SetWindowContextHelpId
UnregisterClassW
SetCapture
ReleaseCapture
CharNextW
CopyAcceleratorTableW
IsRectEmpty
InvalidateRgn
GetNextDlgGroupItem
MessageBeep
RegisterClipboardFormatW
PostThreadMessageW
SetMenuItemBitmaps
GetMenuCheckMarkDimensions
LoadBitmapW
ModifyMenuW
EnableMenuItem
CheckMenuItem
SendDlgItemMessageW
SendDlgItemMessageA
WinHelpW
IsChild
GetCapture
SetWindowsHookExW
CallNextHookEx
GetClassLongW
GetClassNameW
SetPropW
GetPropW
RemovePropW
IsWindow
SetFocus
GetWindowTextLengthW
GetWindowTextW
GetLastActivePopup
SetActiveWindow
GetDlgItem
GetTopWindow
DestroyWindow
UnhookWindowsHookEx
IsWindowEnabled
GetMessagePos
MapWindowPoints
TrackPopupMenuEx
GetKeyState
IsWindowVisible
GetMenu
MessageBoxW
CreateWindowExW
GetClassInfoExW
GetClassInfoW
RegisterClassW
AdjustWindowRectEx
ScreenToClient
EqualRect
PtInRect
GetDlgCtrlID
DefWindowProcW
CallWindowProcW
SetWindowPos
OffsetRect
IntersectRect
SystemParametersInfoA
GetWindowPlacement
GetMenuState
GetMenuItemID
GetMenuItemCount
GetSystemMetrics
IsIconic
FindWindowExW
DrawTextW
SetRect
GetSysColorBrush
SetCursor
WindowFromDC
AppendMenuW
CreatePopupMenu
GetDesktopWindow
LoadIconW
RedrawWindow
DrawFocusRect
InflateRect
CopyRect
CharUpperW
GetFocus
LoadCursorW
SetWindowLongW
GetWindow
DispatchMessageW
TranslateMessage
PostQuitMessage
GetSysColor
PeekMessageW
EnumThreadWindows
GetClientRect
GetParent
InvalidateRect
MapDialogRect
AttachThreadInput
SystemParametersInfoW
GetWindowThreadProcessId
UpdateWindow
ShowWindow
GetWindowLongW
GetWindowRect
RegisterWindowMessageW
SetForegroundWindow
RegisterDeviceNotificationW
GetForegroundWindow
MoveWindow
SetWindowTextW
IsDialogMessageW
EnableWindow
SendMessageW
PostMessageW
GetMessageTime
KillTimer
SetTimer
UnregisterDeviceNotification
GetSubMenu
UnregisterClassA
gdi32
GetClipBox
SetTextColor
SetBkColor
CreateBitmap
SaveDC
RestoreDC
SetBkMode
SetMapMode
ExtTextOutW
Escape
SetViewportOrgEx
OffsetViewportOrgEx
SetViewportExtEx
ScaleViewportExtEx
SetWindowExtEx
ScaleWindowExtEx
ExtSelectClipRgn
RectVisible
CreateSolidBrush
CreateRectRgnIndirect
GetTextMetricsW
GetBkColor
GetTextColor
GetRgnBox
PtVisible
GetDeviceCaps
GetViewportExtEx
GetWindowExtEx
GetStockObject
GetMapMode
SetDIBColorTable
CreateCompatibleBitmap
CreateDIBSection
GetObjectW
DeleteObject
CreateCompatibleDC
SelectObject
BitBlt
DeleteDC
CreateFontW
TextOutW
msimg32
AlphaBlend
comdlg32
GetFileTitleW
winspool.drv
DocumentPropertiesW
OpenPrinterW
ClosePrinter
advapi32
RegDeleteValueW
RegQueryValueW
RegEnumKeyW
RegDeleteKeyW
RegOpenKeyW
RegCreateKeyExW
RegCreateKeyW
RegQueryValueExW
RegCloseKey
RegSetValueExW
RegOpenKeyExW
comctl32
_TrackMouseEvent
InitCommonControlsEx
shlwapi
PathFindExtensionW
PathStripToRootW
PathFindFileNameW
PathIsUNCW
oledlg
OleUIBusyW
ole32
PropVariantClear
CoRegisterMessageFilter
OleFlushClipboard
OleIsCurrentClipboard
CoRevokeClassObject
OleInitialize
CoFreeUnusedLibraries
OleUninitialize
CreateILockBytesOnHGlobal
StgCreateDocfileOnILockBytes
StgOpenStorageOnILockBytes
CoGetClassObject
CLSIDFromString
CLSIDFromProgID
CoTaskMemAlloc
CoInitialize
CoFreeUnusedLibrariesEx
CoInitializeEx
CreateStreamOnHGlobal
StringFromGUID2
CoCreateInstance
CoUninitialize
CoTaskMemFree
oleaut32
SysAllocStringLen
VariantInit
VariantChangeType
VariantClear
SysFreeString
VariantCopy
SysStringLen
SafeArrayDestroy
VariantTimeToSystemTime
SystemTimeToVariantTime
OleCreateFontIndirect
SysAllocString
Sections
.text Size: 284KB - Virtual size: 280KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.rdata Size: 72KB - Virtual size: 71KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.data Size: 16KB - Virtual size: 28KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.rsrc Size: 2.3MB - Virtual size: 2.3MB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE