Analysis

  • max time kernel
    84s
  • max time network
    126s
  • platform
    windows7_x64
  • resource
    win7-20240508-en
  • resource tags

    arch:x64arch:x86image:win7-20240508-enlocale:en-usos:windows7-x64system
  • submitted
    01-07-2024 03:33

General

  • Target

    327614ecbf369a3a766bb48b3077d61cf3af57069c0f96a552fa5f4d21eed23b_NeikiAnalytics.exe

  • Size

    36KB

  • MD5

    b1bb2845282618f5f93e903e05831e20

  • SHA1

    48506d020d487fdb0728b715354e00852c5919d7

  • SHA256

    327614ecbf369a3a766bb48b3077d61cf3af57069c0f96a552fa5f4d21eed23b

  • SHA512

    7d7826d0803dfb1681617700cbd1afc22574cd8c176ffd94a402f9ef040433ffc7038a490971a911c33553038557463a03776dec164e342643413327c1277199

  • SSDEEP

    384:GBt7Br5xjL9AgA71FbhvuNBN2TQ1nrq9SBotHL/XBotHL/k:W7BlpppARFbhknr7BotHDXBotHDk

Score
9/10

Malware Config

Signatures

  • Renames multiple (2204) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\327614ecbf369a3a766bb48b3077d61cf3af57069c0f96a552fa5f4d21eed23b_NeikiAnalytics.exe
    "C:\Users\Admin\AppData\Local\Temp\327614ecbf369a3a766bb48b3077d61cf3af57069c0f96a552fa5f4d21eed23b_NeikiAnalytics.exe"
    1⤵
    • Drops file in Program Files directory
    PID:2056

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-2737914667-933161113-3798636211-1000\desktop.ini.tmp
    Filesize

    36KB

    MD5

    f9f4ddbf85e8f000e4c667b4ecb20028

    SHA1

    a79c270b59381908be9831b13ac60af3a2bc72ee

    SHA256

    734b968482b4ee32dcd6364d7c44e178db9594a2f65de80ba5bcf2a892f045d8

    SHA512

    831e5523b9202b8bfdac33d4ea66273a0f7dae069dab536bf94769547766cf12c05c142e290ef2b8817602f7e0cd9a5d3ce5bac77d4fa6095afb352589c8aebd

  • C:\MSOCache\All Users\{90140000-0011-0000-0000-0000000FF1CE}-C\Office64WW.xml.tmp
    Filesize

    45KB

    MD5

    cdd3d1e1db4e28ad16d8feb0bf7d2738

    SHA1

    0c9256402bde26bbe5d22df85f6b82e843621dc2

    SHA256

    2d81d0048a7002cf6b39ec6238e7030703cff24b26e2de5bdfa71f20c2436b5f

    SHA512

    7d9dd024a3d8db5684e96e3ecf056c73be452af9a2dade1b5707d319f40e660faec397101a57b635c7191660e7a279848aa4877313a9ae5e93a0d50469c3ec6e