Analysis
-
max time kernel
150s -
max time network
155s -
platform
windows10-2004_x64 -
resource
win10v2004-20240508-en -
resource tags
arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system -
submitted
01-07-2024 03:34
Static task
static1
Behavioral task
behavioral1
Sample
327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe
Resource
win7-20240419-en
Behavioral task
behavioral2
Sample
327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe
Resource
win10v2004-20240508-en
General
-
Target
327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe
-
Size
93KB
-
MD5
56a2ba86938b6f9aa953be370dda83a0
-
SHA1
05cf4ea9285ffbc170b373ae21c00dc25f3750ef
-
SHA256
327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978
-
SHA512
ef9f3734130685d4ef33cee9973c9915654446baaf5f5fb6a9ff0f192759db22acb75ff35eb8dd5fcc53d513c137594b2fea6d689f03177776d3537271f5c3ec
-
SSDEEP
1536:W7ZppApUFpEhLfyBtPf50FWkFpPDze/qFsxEhLfyBtPf50FWkFpPDze/qFsAcEhZ:6pWpUFpEhLfyBtPf50FWkFpPDze/qFsg
Malware Config
Signatures
-
Renames multiple (4872) files with added filename extension
This suggests ransomware activity of encrypting all the files on the system.
-
Drops file in Program Files directory 64 IoCs
Processes:
327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exedescription ioc process File created C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0409-1000-0000000FF1CE.xml.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Licenses16\ProjectProMSDNR_Retail-ul-oob.xrm-ms.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\Microsoft.DataIntegration.TransformDataByExample.dll.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Office16\PROOF\msgrammar8.dll.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_OEM_Perp3-ul-oob.xrm-ms.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Office16\LogoImages\ExcelLogoSmall.contrast-black_scale-80.png.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ink\fr-FR\TabTip.exe.mui.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.27\Microsoft.Win32.Primitives.dll.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.2\Microsoft.DiaSymReader.Native.amd64.dll.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Licenses16\VisioPro2019R_Trial-pl.xrm-ms.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Office16\1033\WINWORD.HXS.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Office16\LivePersonaCard\images\default\linkedin_ghost_profile.png.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Office16\MSIPC\lv\msipc.dll.mui.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.27\api-ms-win-core-console-l1-1-0.dll.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Licenses16\OneNoteFreeR_Bypass-ppd.xrm-ms.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Licenses16\ProjectStdO365R_Subscription-ul-oob.xrm-ms.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\7.0.16\ja\PresentationUI.resources.dll.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Java\jdk-1.8\jre\lib\images\cursors\win32_MoveDrop32x32.gif.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Integration\C2RManifest.OneNote.OneNote.x-none.msi.16.x-none.xml.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Licenses16\VisioStdR_Retail-ppd.xrm-ms.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Office16\LogoImages\WinWordLogoSmall.contrast-black_scale-100.png.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Office16\MEDIA\LASER.WAV.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Licenses16\ProPlusR_OEM_Perp5-pl.xrm-ms.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.27\System.Threading.Tasks.Parallel.dll.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\8.0.2\es\System.Windows.Forms.Design.resources.dll.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\8.0.2\System.Threading.AccessControl.dll.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Java\jdk-1.8\jre\lib\deploy\messages_ja.properties.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Integration\C2RManifest.office32mui.msi.16.en-us.xml.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_SubTrial4-ul-oob.xrm-ms.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Licenses16\Professional2019R_Grace-ul-oob.xrm-ms.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Office16\ADDINS\EduWorks Data Streamer Add-In\MsoAriaCApiWrapper.dll.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Office16\LogoImages\PowerPntLogoSmall.contrast-white_scale-180.png.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\6.0.27\cs\System.Windows.Forms.Design.resources.dll.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\6.0.27\UIAutomationProvider.dll.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalPipcR_OEM_Perp-ul-oob.xrm-ms.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Licenses16\VisioStd2019R_Grace-ul-oob.xrm-ms.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\Microsoft.Mashup.Shims.dll.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Office16\api-ms-win-crt-string-l1-1-0.dll.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\6.0.27\pl\System.Windows.Forms.resources.dll.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.27\System.Xml.XPath.XDocument.dll.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Licenses16\Publisher2019VL_MAK_AE-ul-phn.xrm-ms.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Office16\MSQRY32.EXE.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RINTL.pt-br.dll.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_heb.xml.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\6.0.27\PresentationFramework.Classic.dll.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\8.0.2\de\UIAutomationClientSideProviders.resources.dll.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Java\jdk-1.8\jre\lib\fonts\LucidaSansRegular.ttf.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Licenses16\PersonalPipcDemoR_BypassTrial365-ppd.xrm-ms.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Office16\ODBC Drivers\Salesforce\lib\zlibwapi.dll.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.NETCore.App\7.0.16\System.Security.Cryptography.OpenSsl.dll.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Java\jre-1.8\lib\tzdb.dat.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ink\et-EE\tipresx.dll.mui.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\6.0.27\ko\System.Windows.Controls.Ribbon.resources.dll.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\7.0.16\D3DCompiler_47_cor3.dll.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\7.0.16\pt-BR\PresentationFramework.resources.dll.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Java\jdk-1.8\jre\bin\wsdetect.dll.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Java\jdk-1.8\jre\lib\fonts\LucidaBrightDemiItalic.ttf.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\Interop.MSDASC.dll.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RINTL.fr-fr.dll.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\7.0.16\zh-Hant\System.Windows.Forms.resources.dll.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Java\jre-1.8\bin\api-ms-win-core-debug-l1-1-0.dll.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Java\jre-1.8\lib\security\policy\unlimited\local_policy.jar.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Office16\api-ms-win-core-localization-l1-2-0.dll.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ink\en-GB\tipresx.dll.mui.tmp 327ef6becaee1d8ae8b3b604e385d798c03f158cfb0bca547976b6b2edbba978_NeikiAnalytics.exe
Processes
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\$Recycle.Bin\S-1-5-21-1337824034-2731376981-3755436523-1000\desktop.ini.tmpFilesize
93KB
MD56d47927d151da8e015bb5cfc740feb6c
SHA1c9f93638454179a72401102b4cf05dd154615e89
SHA256c9406763661a145c038a7b7c9c92866faa38e30c140f9f69be4650245c1a6a94
SHA512a762d8ad451a78644c77eab415d49bdb93cdadabf031a374dc02968a9992c755dee1c5d653d4ffffa01e71df2abd62242df1ce556ddc7b3a7e3917531b3de635
-
C:\Program Files\7-Zip\7-zip.dll.tmpFilesize
192KB
MD557cead1d3e571952bdcbf9a63e85f13c
SHA196240d613fc8d476b1f4e464d1f003cd4ca5be74
SHA25600ce21ea1b8d177ed919cc906f169e3296d24d0db35d59a59195a3b5d6ebb327
SHA512a338772c8e68cccfb045f68a529d54a10dca6deecfcd46def35deb6b62bf30c26a342d4af519d91e11aec85b8dc2bf8244e01678e5ddf9aa706aff67c506842b