Analysis
-
max time kernel
120s -
max time network
129s -
platform
windows7_x64 -
resource
win7-20240611-en -
resource tags
arch:x64arch:x86image:win7-20240611-enlocale:en-usos:windows7-x64system -
submitted
30-06-2024 20:55
Behavioral task
behavioral1
Sample
18f830e67899c6cbc912e1956e9b42aa64608e86aeb5844df24588026e3bf526_NeikiAnalytics.pdf
Resource
win7-20240611-en
Behavioral task
behavioral2
Sample
18f830e67899c6cbc912e1956e9b42aa64608e86aeb5844df24588026e3bf526_NeikiAnalytics.pdf
Resource
win10v2004-20240611-en
General
-
Target
18f830e67899c6cbc912e1956e9b42aa64608e86aeb5844df24588026e3bf526_NeikiAnalytics.pdf
-
Size
89KB
-
MD5
f390ea6fbe2d62d04da07476f6b362e0
-
SHA1
08cd80600b6c900227bbd9323488264d0962a98d
-
SHA256
18f830e67899c6cbc912e1956e9b42aa64608e86aeb5844df24588026e3bf526
-
SHA512
e91435d3c9330ace0b3a44f93b0dd3a3d7336cedccdd08df1683bde28e7ddcbb4888801fa50abd9128187d84d6a78a37d9a4342938078ee210a3208b80b264d7
-
SSDEEP
1536:cw/FMBiJuJX8grSuVa9eXjOzEAil5iEdrk8yoPSEdLNWg77uSd:lFMCuJMgdwWCzJak8yoKEVf3L
Malware Config
Signatures
-
Suspicious behavior: GetForegroundWindowSpam 1 IoCs
Processes:
AcroRd32.exepid process 1732 AcroRd32.exe -
Suspicious use of SetWindowsHookEx 3 IoCs
Processes:
AcroRd32.exepid process 1732 AcroRd32.exe 1732 AcroRd32.exe 1732 AcroRd32.exe
Processes
-
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe"C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe" "C:\Users\Admin\AppData\Local\Temp\18f830e67899c6cbc912e1956e9b42aa64608e86aeb5844df24588026e3bf526_NeikiAnalytics.pdf"1⤵
- Suspicious behavior: GetForegroundWindowSpam
- Suspicious use of SetWindowsHookEx
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Users\Admin\AppData\Roaming\Adobe\Acrobat\9.0\SharedDataEventsFilesize
3KB
MD5a035aec327a949bf6a79dbe5e63f6f89
SHA1cde5ea2b0823767c379440f81838d348219c244a
SHA256596fb6f8c997f2b6d78dc0bcc20e9c55eb2ee8ff60108086838768c6e80bdff2
SHA5124dc6212da9f56317c01efd23ec31dcf6dab11132cd0322f21f617db80dd7c5ddb4844e084e7eeb566dcfc97ab4dafd07cd3818fb09da4d7df5501bf901f5408b