Analysis

  • max time kernel
    142s
  • max time network
    119s
  • platform
    windows7_x64
  • resource
    win7-20240508-en
  • resource tags

    arch:x64arch:x86image:win7-20240508-enlocale:en-usos:windows7-x64system
  • submitted
    01-07-2024 03:30

General

  • Target

    323c8da39fd43b3493f572fea68531edfd4e55061bc8ab0be5816eaed7711acf_NeikiAnalytics.exe

  • Size

    81KB

  • MD5

    dd33ec33103ef8599816207d91ec06f0

  • SHA1

    1c1fd287a24a570fa934c9a22f9e04141d55e0da

  • SHA256

    323c8da39fd43b3493f572fea68531edfd4e55061bc8ab0be5816eaed7711acf

  • SHA512

    ccdaea4a82c3d3b5b82992d4b4493e615c9e96f88af880d528081625f3a3f58d571a5370c8068498c0b0dfe497649a79e44f71695ba74681c2697c087a269e07

  • SSDEEP

    768:W7BlpDpARFbhYQkQjjIXYvPXzWPXzK3733uF4V7en5c5HChCrmh1444REXBwzEXO:W7ZDpApYbWjIoPyPoLzV7c6Sh1X0

Score
9/10

Malware Config

Signatures

  • Renames multiple (2839) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\323c8da39fd43b3493f572fea68531edfd4e55061bc8ab0be5816eaed7711acf_NeikiAnalytics.exe
    "C:\Users\Admin\AppData\Local\Temp\323c8da39fd43b3493f572fea68531edfd4e55061bc8ab0be5816eaed7711acf_NeikiAnalytics.exe"
    1⤵
    • Drops file in Program Files directory
    PID:1304

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-3691908287-3775019229-3534252667-1000\desktop.ini.tmp
    Filesize

    81KB

    MD5

    b5a4a0a4953a20725df65c4c0492df71

    SHA1

    404c4af77ae9745a2a644151058dd38adda93844

    SHA256

    ea2091576921dc828e0afdfb049d94982a5a9ff5748d387bfdade2171f48a3c9

    SHA512

    2946d4091df493f396697c237524cd2b4a7a96893d53c9e835df36e170600df2a87d02129702085e85d4cd4a02338bb59442420440a84836f158aba07ad2a19b

  • C:\MSOCache\All Users\{90140000-0011-0000-0000-0000000FF1CE}-C\Office64WW.xml.tmp
    Filesize

    90KB

    MD5

    f2b37e5311c59ac1b8b010a3337fa36f

    SHA1

    6c99ec5a22044c98d1179e902fd344df5e54dcb2

    SHA256

    97ec31299607e756483f2081e1b4518f41a0e830848d1abc1068f735ec747fe8

    SHA512

    5780306b305bd248ebbcd4367cb3367c2ce61c9e6318e4023dd3fc9101c708b14da3cb64f19f5a34d4fd07ea2ab6f7a949d1d8c2cabc2ed50b724d9b23ab247c