Analysis
-
max time kernel
9s -
max time network
136s -
platform
windows10-2004_x64 -
resource
win10v2004-20240611-en -
resource tags
arch:x64arch:x86image:win10v2004-20240611-enlocale:en-usos:windows10-2004-x64system -
submitted
01-07-2024 02:06
Static task
static1
Behavioral task
behavioral1
Sample
2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe
Resource
win7-20240508-en
Behavioral task
behavioral2
Sample
2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe
Resource
win10v2004-20240611-en
General
-
Target
2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe
-
Size
1.4MB
-
MD5
bb79e055b6ad691023039e7a523bcbb0
-
SHA1
537754dc925ba1994fc7f4480cb4edd5a372bae6
-
SHA256
2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86
-
SHA512
c58dd2310091fb839f4b558f6f634b12d1bdd768bdee0739717d3cbfc458b01971809e853dc719a4dcfdc5dda015ceac3c19493f22cc8a55d1c61eb9b50ca906
-
SSDEEP
24576:Ch2ZjGCCr8Hf/NVPrusZmWXNRJNfl5cWVElB958RfcUWiJEvJmZ83tmEljXeAY4e:CkZ9Hf/NIs/N/d4WVEj78uFiJEvJo8IL
Malware Config
Signatures
-
Checks computer location settings 2 TTPs 6 IoCs
Looks up country code configured in the registry, likely geofence.
Processes:
2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exedescription ioc process Key value queried \REGISTRY\USER\S-1-5-21-3665033694-1447845302-680750983-1000\Control Panel\International\Geo\Nation 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe Key value queried \REGISTRY\USER\S-1-5-21-3665033694-1447845302-680750983-1000\Control Panel\International\Geo\Nation 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe Key value queried \REGISTRY\USER\S-1-5-21-3665033694-1447845302-680750983-1000\Control Panel\International\Geo\Nation 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe Key value queried \REGISTRY\USER\S-1-5-21-3665033694-1447845302-680750983-1000\Control Panel\International\Geo\Nation 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe Key value queried \REGISTRY\USER\S-1-5-21-3665033694-1447845302-680750983-1000\Control Panel\International\Geo\Nation 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe Key value queried \REGISTRY\USER\S-1-5-21-3665033694-1447845302-680750983-1000\Control Panel\International\Geo\Nation 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe -
Reads user/profile data of web browsers 2 TTPs
Infostealers often target stored browser data, which can include saved credentials etc.
-
Adds Run key to start application 2 TTPs 1 IoCs
Processes:
2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exedescription ioc process Set value (str) \REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\mssrv32 = "C:\\Windows\\mssrv.exe" 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe -
Enumerates connected drives 3 TTPs 23 IoCs
Attempts to read the root path of hard drives other than the default C: drive.
Processes:
2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exedescription ioc process File opened (read-only) \??\N: 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File opened (read-only) \??\V: 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File opened (read-only) \??\Y: 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File opened (read-only) \??\G: 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File opened (read-only) \??\H: 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File opened (read-only) \??\I: 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File opened (read-only) \??\L: 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File opened (read-only) \??\W: 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File opened (read-only) \??\A: 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File opened (read-only) \??\B: 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File opened (read-only) \??\E: 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File opened (read-only) \??\Z: 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File opened (read-only) \??\P: 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File opened (read-only) \??\R: 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File opened (read-only) \??\J: 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File opened (read-only) \??\K: 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File opened (read-only) \??\M: 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File opened (read-only) \??\T: 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File opened (read-only) \??\U: 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File opened (read-only) \??\X: 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File opened (read-only) \??\O: 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File opened (read-only) \??\Q: 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File opened (read-only) \??\S: 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe -
Drops file in System32 directory 4 IoCs
Processes:
2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exedescription ioc process File created C:\Windows\SysWOW64\config\systemprofile\brasilian gang bang beast [free] gorgeoushorny .avi.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Windows\System32\DriverStore\Temp\lingerie girls femdom .mpg.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Windows\SysWOW64\FxsTmp\japanese nude lingerie [milf] glans .mpg.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Windows\SysWOW64\IME\SHARED\beast licking titts .mpeg.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe -
Drops file in Program Files directory 20 IoCs
Processes:
2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exedescription ioc process File created C:\Program Files\Microsoft Office\root\vfs\ProgramFilesX64\Microsoft SQL Server\130\Shared\beast lesbian .zip.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\vfs\ProgramFilesX86\Microsoft SQL Server\130\Shared\danish porn horse catfight titts shower .avi.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Program Files\Windows Sidebar\Shared Gadgets\sperm uncut feet bedroom (Liz).zip.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Program Files (x86)\Common Files\Microsoft Shared\brasilian cumshot blowjob catfight (Melissa).zip.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Program Files (x86)\Google\Temp\tyrkish kicking sperm voyeur hole wifey .mpg.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Program Files (x86)\Google\Update\Download\russian animal trambling full movie feet 40+ .rar.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\russian nude xxx [bangbus] 40+ .mpeg.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\swedish cum blowjob girls cock (Ashley,Tatjana).zip.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Program Files (x86)\Microsoft\EdgeUpdate\Download\russian nude blowjob hot (!) circumcision .mpg.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Program Files (x86)\Windows Sidebar\Shared Gadgets\japanese nude hardcore public glans YEâPSè& .mpg.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Program Files\WindowsApps\Microsoft.WindowsMaps_5.1906.1972.0_x64__8wekyb3d8bbwe\Assets\Images\PrintAndShare\danish nude xxx hidden swallow .mpg.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Program Files (x86)\Microsoft\Temp\EUA671.tmp\hardcore sleeping balls .rar.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\hardcore voyeur cock .avi.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\unified-share\italian beastiality blowjob voyeur titts girly .zip.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Program Files (x86)\Microsoft\EdgeUpdate\Install\{CFD7095D-03FC-4A5C-948B-20FAB1B69302}\EDGEMITMP_4CFFA.tmp\gay sleeping titts high heels .mpg.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\bukkake [milf] feet beautyfull .rar.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Templates\trambling [free] lady .mpeg.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Program Files (x86)\Microsoft\Temp\american cum lingerie full movie titts girly (Sylvia).rar.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\Updates\Download\brasilian kicking lingerie catfight circumcision .zip.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\IDTemplates\italian animal hardcore sleeping penetration .mpeg.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe -
Drops file in Windows directory 24 IoCs
Processes:
2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exedescription ioc process File created C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\sperm [bangbus] boots (Kathrin,Jade).avi.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Windows\assembly\temp\russian animal gay several models glans .rar.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Templates\hardcore uncut .mpeg.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Windows\ServiceProfiles\NetworkService\Downloads\japanese kicking xxx hidden .zip.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Windows\mssrv.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Windows\assembly\tmp\japanese handjob gay [bangbus] .zip.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Windows\InputMethod\SHARED\american kicking bukkake full movie wifey .mpg.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.GroupPolicy.AdmTmplEditor.Resources\lesbian licking upskirt .rar.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.GroupPolicy.AdmTmplEditor.Resources\sperm uncut .zip.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Windows\PLA\Templates\indian animal gay voyeur high heels .mpeg.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Templates\trambling [milf] feet upskirt (Janette).zip.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\hardcore lesbian .zip.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Windows\assembly\NativeImages_v4.0.30319_32\Temp\swedish action blowjob several models (Liz).rar.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Windows\assembly\NativeImages_v4.0.30319_64\Temp\danish nude trambling catfight hole bedroom (Sarah).mpg.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Windows\CbsTemp\russian animal sperm hidden traffic (Ashley,Jade).avi.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Windows\Downloaded Program Files\russian fetish lesbian voyeur femdom .rar.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.GroupPolicy.AdmTmplEditor\black gang bang trambling [milf] fishy .avi.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Windows\security\templates\lesbian several models feet beautyfull (Janette).avi.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\xxx [bangbus] (Samantha).mpeg.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Windows\SoftwareDistribution\Download\lingerie catfight feet Ôï .mpg.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Windows\SoftwareDistribution\Download\SharedFileCache\british lingerie full movie .zip.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\gay [milf] .zip.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.GroupPolicy.AdmTmplEditor\black cum beast several models wifey .avi.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe File created C:\Windows\ServiceProfiles\LocalService\Downloads\american gang bang hardcore voyeur 40+ (Sonja,Liz).avi.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe -
Enumerates physical storage devices 1 TTPs
Attempts to interact with connected storage/optical drive(s).
-
Suspicious behavior: EnumeratesProcesses 30 IoCs
Processes:
2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exepid process 2280 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2280 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2376 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2376 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2280 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2280 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 4292 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 4292 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 4956 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 4956 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2280 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2280 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2376 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2376 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 3648 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 3648 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 4292 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 976 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 976 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 4292 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2280 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2280 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 3756 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 3756 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2376 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2376 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 848 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 848 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 4956 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 4956 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe -
Suspicious use of WriteProcessMemory 39 IoCs
Processes:
2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exedescription pid process target process PID 2280 wrote to memory of 2376 2280 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe PID 2280 wrote to memory of 2376 2280 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe PID 2280 wrote to memory of 2376 2280 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe PID 2280 wrote to memory of 4292 2280 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe PID 2280 wrote to memory of 4292 2280 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe PID 2280 wrote to memory of 4292 2280 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe PID 2376 wrote to memory of 4956 2376 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe PID 2376 wrote to memory of 4956 2376 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe PID 2376 wrote to memory of 4956 2376 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe PID 4292 wrote to memory of 3648 4292 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe PID 4292 wrote to memory of 3648 4292 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe PID 4292 wrote to memory of 3648 4292 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe PID 2280 wrote to memory of 976 2280 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe PID 2280 wrote to memory of 976 2280 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe PID 2280 wrote to memory of 976 2280 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe PID 2376 wrote to memory of 3756 2376 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe PID 2376 wrote to memory of 3756 2376 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe PID 2376 wrote to memory of 3756 2376 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe PID 4956 wrote to memory of 848 4956 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe PID 4956 wrote to memory of 848 4956 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe PID 4956 wrote to memory of 848 4956 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe PID 4292 wrote to memory of 2800 4292 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe PID 4292 wrote to memory of 2800 4292 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe PID 4292 wrote to memory of 2800 4292 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe PID 3648 wrote to memory of 2992 3648 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe PID 3648 wrote to memory of 2992 3648 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe PID 3648 wrote to memory of 2992 3648 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe PID 2376 wrote to memory of 2080 2376 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe PID 2376 wrote to memory of 2080 2376 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe PID 2376 wrote to memory of 2080 2376 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe PID 2280 wrote to memory of 2004 2280 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe PID 2280 wrote to memory of 2004 2280 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe PID 2280 wrote to memory of 2004 2280 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe PID 4956 wrote to memory of 2344 4956 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe PID 4956 wrote to memory of 2344 4956 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe PID 4956 wrote to memory of 2344 4956 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe PID 976 wrote to memory of 2820 976 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe PID 976 wrote to memory of 2820 976 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe PID 976 wrote to memory of 2820 976 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe 2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe
Processes
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"1⤵
- Checks computer location settings
- Adds Run key to start application
- Enumerates connected drives
- Drops file in System32 directory
- Drops file in Program Files directory
- Drops file in Windows directory
- Suspicious behavior: EnumeratesProcesses
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"2⤵
- Checks computer location settings
- Suspicious behavior: EnumeratesProcesses
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"3⤵
- Checks computer location settings
- Suspicious behavior: EnumeratesProcesses
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
- Suspicious behavior: EnumeratesProcesses
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"6⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"7⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"8⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"7⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"7⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"6⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"7⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"6⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"6⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"6⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"6⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"7⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"6⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"6⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"6⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"6⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"6⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"7⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"6⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"6⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"6⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"6⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"6⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"6⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"3⤵
- Suspicious behavior: EnumeratesProcesses
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"6⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"7⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"6⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"6⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"6⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"6⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"3⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"6⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"3⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"3⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"3⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"3⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"3⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"2⤵
- Checks computer location settings
- Suspicious behavior: EnumeratesProcesses
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"3⤵
- Checks computer location settings
- Suspicious behavior: EnumeratesProcesses
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"6⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"7⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"6⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"6⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"6⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"6⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"6⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"6⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"6⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"6⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"3⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"6⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"6⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"6⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"3⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"3⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"3⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"3⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"3⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"2⤵
- Checks computer location settings
- Suspicious behavior: EnumeratesProcesses
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"3⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"6⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"3⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"3⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"3⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"3⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"3⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"2⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"3⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"3⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"3⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"3⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"3⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"2⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"3⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"3⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"3⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"3⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"2⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"3⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"3⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"2⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"3⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"2⤵
-
C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\2d879a5f2a86c1a8dcb59885cc830b012a2a171d0c79aa0582f22d34f94f7b86_NeikiAnalytics.exe"2⤵
-
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --field-trial-handle=3028,i,7977653611488681184,6839495125838449898,262144 --variations-seed-version --mojo-platform-channel-handle=3884 /prefetch:81⤵
Network
MITRE ATT&CK Matrix ATT&CK v13
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\hardcore voyeur cock .avi.exeFilesize
989KB
MD5e904899200da7dd346d14d085466794d
SHA117d00d746aa5bf947446765fc75b5628256bb7ba
SHA25638e071d8a511a17a108d44c0d102a9327ef2d90f90f5429d378a6a4f83d25207
SHA51215055e8b0f402e570a8aa6cc02c43934e7f1423a8d0141cc66c1581cc521b1d43f86071bcb0f5d59dca9a79ce985308595e8a8258e1331934a95ca652bdda7c7