Analysis

  • max time kernel
    149s
  • max time network
    127s
  • platform
    windows7_x64
  • resource
    win7-20240419-en
  • resource tags

    arch:x64arch:x86image:win7-20240419-enlocale:en-usos:windows7-x64system
  • submitted
    01-07-2024 03:34

General

  • Target

    327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe

  • Size

    93KB

  • MD5

    56a2ba86938b6f9aa953be370dda83a0

  • SHA1

    05cf4ea9285ffbc170b373ae21c00dc25f3750ef

  • SHA256

    327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978

  • SHA512

    ef9f3734130685d4ef33cee9973c9915654446baaf5f5fb6a9ff0f192759db22acb75ff35eb8dd5fcc53d513c137594b2fea6d689f03177776d3537271f5c3ec

  • SSDEEP

    1536:W7ZppApUFpEhLfyBtPf50FWkFpPDze/qFsxEhLfyBtPf50FWkFpPDze/qFsAcEhZ:6pWpUFpEhLfyBtPf50FWkFpPDze/qFsg

Score
9/10

Malware Config

Signatures

  • Renames multiple (3267) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe
    "C:\Users\Admin\AppData\Local\Temp\327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe"
    1⤵
    • Drops file in Program Files directory
    PID:2420

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-481678230-3773327859-3495911762-1000\desktop.ini.tmp
    Filesize

    93KB

    MD5

    b1368bafe31f4903309193de16677286

    SHA1

    ebe5f1b9517f6b0d007afbdfa7a989cae3d071cd

    SHA256

    2eb72ac9950a99a677d0721989b9d240b62df06568f5adbf090a7eaabb2d1632

    SHA512

    613e9490eb296ed0b4268148d83123ace2e4fba5b735a5194fbc3e667489f55ec65b3794588617456a521314ae34aafd2b043528d26d76595032feb971691ebe

  • C:\MSOCache\All Users\{90140000-0011-0000-0000-0000000FF1CE}-C\Office64WW.xml.tmp
    Filesize

    102KB

    MD5

    2b91521e19679fc9a755565152a64edf

    SHA1

    7e57f01e0c2d4c91ceb1a814df2c1532a8d29027

    SHA256

    e401f5cedebed454f4033b10a56ca858a5a98210e3b08f7d2f4f0eb117d1cc48

    SHA512

    4b8d6dd26c0a088cf481849d60052db0e3ccba44e170d3bb050a2b25c4d9505cb835b2d96576c4908cec385e505ef4f89f8513fa9690c506bc55474ae8b2ebb1