Analysis

  • max time kernel
    150s
  • max time network
    47s
  • platform
    windows10-2004_x64
  • resource
    win10v2004-20240508-en
  • resource tags

    arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system
  • submitted
    01-07-2024 03:30

General

  • Target

    323c8da39fd43b3493f572fea68531edfd4e55061bc8ab0be5816eaed7711acf_NeikiAnalytics.exe

  • Size

    81KB

  • MD5

    dd33ec33103ef8599816207d91ec06f0

  • SHA1

    1c1fd287a24a570fa934c9a22f9e04141d55e0da

  • SHA256

    323c8da39fd43b3493f572fea68531edfd4e55061bc8ab0be5816eaed7711acf

  • SHA512

    ccdaea4a82c3d3b5b82992d4b4493e615c9e96f88af880d528081625f3a3f58d571a5370c8068498c0b0dfe497649a79e44f71695ba74681c2697c087a269e07

  • SSDEEP

    768:W7BlpDpARFbhYQkQjjIXYvPXzWPXzK3733uF4V7en5c5HChCrmh1444REXBwzEXO:W7ZDpApYbWjIoPyPoLzV7c6Sh1X0

Score
9/10

Malware Config

Signatures

  • Renames multiple (4868) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\323c8da39fd43b3493f572fea68531edfd4e55061bc8ab0be5816eaed7711acf_NeikiAnalytics.exe
    "C:\Users\Admin\AppData\Local\Temp\323c8da39fd43b3493f572fea68531edfd4e55061bc8ab0be5816eaed7711acf_NeikiAnalytics.exe"
    1⤵
    • Drops file in Program Files directory
    PID:1508

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-1337824034-2731376981-3755436523-1000\desktop.ini.tmp
    Filesize

    81KB

    MD5

    49bec1f5c694b2923c43cc4c7e07be1a

    SHA1

    00212c85a152c72262d4365f5d88623266bbb562

    SHA256

    3172744a2815e6f1833f54c17337644ac4c47af228281d98a190be4e7a88ecee

    SHA512

    c817b13ca6f427fb04d0eb017c95f6463e9754c82f28f429a907c0589b25bb68a4b75aa33a2415211afa023c6e6a702c72f48801f7b7d734fbeb6effc2dae9e2

  • C:\Program Files\7-Zip\7-zip.dll.tmp
    Filesize

    180KB

    MD5

    ca0b56e174918a15f7446c4e2a1a3efb

    SHA1

    69bd1dd9418e78e26512877ba4e45155e0693b1e

    SHA256

    c5b5789646bb9d6a05fb0e77d390c7a8958c7a09e64673df32e0f8e4e2f7b025

    SHA512

    0c72b8a958fa254f2ae57b4c653ab4120067ed087feef5412775bb41c56062fbd1789d9202b35d50f3079b8487d037333dffee8ad507d95aff3484abce437de2