et_CloseToken
et_FindToken
et_GenPID
et_GenRandom
et_GenSOPIN
et_GetSN
et_OpenToken
et_Read
et_Verify
et_Write
Behavioral task
behavioral1
Sample
29d26d8b759d0ca77cea9b648e92ddd315919d818b67b804e0e22f2db450a43d_NeikiAnalytics.dll
Resource
win7-20240508-en
Behavioral task
behavioral2
Sample
29d26d8b759d0ca77cea9b648e92ddd315919d818b67b804e0e22f2db450a43d_NeikiAnalytics.dll
Resource
win10v2004-20240226-en
Target
29d26d8b759d0ca77cea9b648e92ddd315919d818b67b804e0e22f2db450a43d_NeikiAnalytics.exe
Size
5.7MB
MD5
ae9ba2b885afa99fad085ee1ea81c7e0
SHA1
8cd6b32ad8a6e20eb632aa03917dc286382a93fe
SHA256
29d26d8b759d0ca77cea9b648e92ddd315919d818b67b804e0e22f2db450a43d
SHA512
52cc127fc5c238d791799fef7af4cf873094376c3493e2800eb447c496e5efd582799cbf1e76b88976670bb1f96c4b01438c84e58db5ab7ba2c852b7247de9f7
SSDEEP
98304:4WMdD6IYebdqFIjW9vGa6JxeCb1/HLk2zJ+HBq9AFRflUlrpdBUFbNhm6VWhB7Fj:LIYebdrEvxaBh/rPuBqQUnd+lNhnQH7x
Processes:
resource | yara_rule |
---|---|
sample | vmprotect |
Checks for missing Authenticode signature.
Processes:
resource |
---|
29d26d8b759d0ca77cea9b648e92ddd315919d818b67b804e0e22f2db450a43d_NeikiAnalytics.exe |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
GetVersion
GetVersionExA
VirtualQuery
LocalAlloc
LocalFree
GetModuleFileNameW
GetProcessAffinityMask
SetProcessAffinityMask
SetThreadAffinityMask
Sleep
ExitProcess
FreeLibrary
LoadLibraryA
GetModuleHandleA
GetProcAddress
SetWindowPos
GetUserObjectInformationW
GetProcessWindowStation
GetUserObjectInformationW
SelectObject
SetupDiEnumDeviceInterfaces
ClosePrinter
RegCreateKeyExA
PathFileExistsA
DragQueryFileA
ImageList_EndDrag
WTSSendMessageW
et_CloseToken
et_FindToken
et_GenPID
et_GenRandom
et_GenSOPIN
et_GetSN
et_OpenToken
et_Read
et_Verify
et_Write
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
IMAGE_SCN_CNT_CODE
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_CNT_CODE
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ