Analysis

  • max time kernel
    150s
  • max time network
    155s
  • platform
    windows10-2004_x64
  • resource
    win10v2004-20240508-en
  • resource tags

    arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system
  • submitted
    01-07-2024 03:34

General

  • Target

    327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe

  • Size

    93KB

  • MD5

    56a2ba86938b6f9aa953be370dda83a0

  • SHA1

    05cf4ea9285ffbc170b373ae21c00dc25f3750ef

  • SHA256

    327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978

  • SHA512

    ef9f3734130685d4ef33cee9973c9915654446baaf5f5fb6a9ff0f192759db22acb75ff35eb8dd5fcc53d513c137594b2fea6d689f03177776d3537271f5c3ec

  • SSDEEP

    1536:W7ZppApUFpEhLfyBtPf50FWkFpPDze/qFsxEhLfyBtPf50FWkFpPDze/qFsAcEhZ:6pWpUFpEhLfyBtPf50FWkFpPDze/qFsg

Score
9/10

Malware Config

Signatures

  • Renames multiple (4872) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe
    "C:\Users\Admin\AppData\Local\Temp\327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe"
    1⤵
    • Drops file in Program Files directory
    PID:744

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-1337824034-2731376981-3755436523-1000\desktop.ini.tmp
    Filesize

    93KB

    MD5

    6d47927d151da8e015bb5cfc740feb6c

    SHA1

    c9f93638454179a72401102b4cf05dd154615e89

    SHA256

    c9406763661a145c038a7b7c9c92866faa38e30c140f9f69be4650245c1a6a94

    SHA512

    a762d8ad451a78644c77eab415d49bdb93cdadabf031a374dc02968a9992c755dee1c5d653d4ffffa01e71df2abd62242df1ce556ddc7b3a7e3917531b3de635

  • C:\Program Files\7-Zip\7-zip.dll.tmp
    Filesize

    192KB

    MD5

    57cead1d3e571952bdcbf9a63e85f13c

    SHA1

    96240d613fc8d476b1f4e464d1f003cd4ca5be74

    SHA256

    00ce21ea1b8d177ed919cc906f169e3296d24d0db35d59a59195a3b5d6ebb327

    SHA512

    a338772c8e68cccfb045f68a529d54a10dca6deecfcd46def35deb6b62bf30c26a342d4af519d91e11aec85b8dc2bf8244e01678e5ddf9aa706aff67c506842b