Analysis

  • max time kernel
    149s
  • max time network
    123s
  • platform
    windows7_x64
  • resource
    win7-20240508-en
  • resource tags

    arch:x64arch:x86image:win7-20240508-enlocale:en-usos:windows7-x64system
  • submitted
    01-07-2024 02:41

General

  • Target

    2f671b32a2522a38b652f5378ac0e91efa59aa6d508ab672df642f00d82b9de6_NeikiAnalytics.exe

  • Size

    40KB

  • MD5

    feb761cc1b3b2f8626a71194efa46510

  • SHA1

    eafe20d4f79124efcafc0b704cbad63856f02c2b

  • SHA256

    2f671b32a2522a38b652f5378ac0e91efa59aa6d508ab672df642f00d82b9de6

  • SHA512

    eac6c88345f34f0c28ce2fdb476553c2f1a4507264b24d17d007a4d9777384acfd01439bafdf5bb06cfe0378ff43940b614765dc4024b2b7ee574138d0663f9a

  • SSDEEP

    768:W7BlpppARFbhbt7Y7FoICOiJfoICOiJQ444Zqu:W7ZppApWmjXs

Score
9/10

Malware Config

Signatures

  • Renames multiple (3451) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\2f671b32a2522a38b652f5378ac0e91efa59aa6d508ab672df642f00d82b9de6_NeikiAnalytics.exe
    "C:\Users\Admin\AppData\Local\Temp\2f671b32a2522a38b652f5378ac0e91efa59aa6d508ab672df642f00d82b9de6_NeikiAnalytics.exe"
    1⤵
    • Drops file in Program Files directory
    PID:1612

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-2737914667-933161113-3798636211-1000\desktop.ini.tmp
    Filesize

    40KB

    MD5

    e779cead9f9e729bbb10eb5d04fc7fc3

    SHA1

    065010e9867fa1dc88eb37832e76f784763e6c09

    SHA256

    5432898eb462821c8c202b5a76dba59620809fccd087aaf400b1813a185cdd15

    SHA512

    a10fb8b7ddff909b4e4553c87d37e12a49f60e3c5727840cb4128a06041042c90d7c027b78d46008a4d31940bdbb50a81284b677befe99ec5bc771895a82e110

  • C:\MSOCache\All Users\{90140000-0011-0000-0000-0000000FF1CE}-C\Office64WW.xml.tmp
    Filesize

    49KB

    MD5

    ee85b1ae6752ad279646f798e5642a3e

    SHA1

    e445f6cf335e20a961526bb3d1e0738cf655ece6

    SHA256

    2f08a9577193350fb9e5b7ded25882ab913318e0ff0fc45029e728b770821f11

    SHA512

    08c14d1a48d53bfab306b70d8532ab238cc539e7a106f18ddb4c47eb4288291ca2ce2a984bee32939d93986d5c1e46d78de91a8d643e26c9664221f06a5d8d62