Analysis
-
max time kernel
121s -
max time network
127s -
platform
windows7_x64 -
resource
win7-20240508-en -
resource tags
arch:x64arch:x86image:win7-20240508-enlocale:en-usos:windows7-x64system -
submitted
01-07-2024 00:45
Behavioral task
behavioral1
Sample
281845c3a4e0b247b9e3e90e15a6d43941b5fa82e8c40cee05ae62159b8305e6_NeikiAnalytics.pdf
Resource
win7-20240508-en
Behavioral task
behavioral2
Sample
281845c3a4e0b247b9e3e90e15a6d43941b5fa82e8c40cee05ae62159b8305e6_NeikiAnalytics.pdf
Resource
win10v2004-20240508-en
General
-
Target
281845c3a4e0b247b9e3e90e15a6d43941b5fa82e8c40cee05ae62159b8305e6_NeikiAnalytics.pdf
-
Size
74KB
-
MD5
23c6308e9b492820d4337bcad8d0c8c0
-
SHA1
9f58b5146e911044d10b8dc648e4f69834be38e7
-
SHA256
281845c3a4e0b247b9e3e90e15a6d43941b5fa82e8c40cee05ae62159b8305e6
-
SHA512
0da3846cf4635ece8eff47e73d49ef8b6cad21391c801c43d5a356d6f1fca44769bbd23ee70493edc39253ee5877a8d7e410a1a03e636ac4bb3a1b442cf133c6
-
SSDEEP
1536:LUF0tGGLiTX2uCPst9jbTpAb3y5sTuCCngDnQk4ygVGFZghUNOiB2E:Q+oXCWjbii+TubGnghyL
Malware Config
Signatures
-
Suspicious behavior: GetForegroundWindowSpam 1 IoCs
Processes:
AcroRd32.exepid process 2184 AcroRd32.exe -
Suspicious use of SetWindowsHookEx 3 IoCs
Processes:
AcroRd32.exepid process 2184 AcroRd32.exe 2184 AcroRd32.exe 2184 AcroRd32.exe
Processes
-
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe"C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe" "C:\Users\Admin\AppData\Local\Temp\281845c3a4e0b247b9e3e90e15a6d43941b5fa82e8c40cee05ae62159b8305e6_NeikiAnalytics.pdf"1⤵
- Suspicious behavior: GetForegroundWindowSpam
- Suspicious use of SetWindowsHookEx
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Users\Admin\AppData\Roaming\Adobe\Acrobat\9.0\SharedDataEventsFilesize
3KB
MD5c731bd2f22c08f49fdb1c057fe9f2060
SHA149dbef141cad67bbb6891ad2b8f3fa92a5a42637
SHA2566de2393d9dd216252b5f1f72b14697d72b03c0c47638d2c88702d7e44f4c36f6
SHA512006826e34f90affc77c2c288b7639f1769bd231d67b987fda79883fb68ce62448db406722df58274cd49d2c3ed04f345094fe116fb411b405ca1bd1078c81153