Analysis
-
max time kernel
122s -
max time network
126s -
platform
windows7_x64 -
resource
win7-20240611-en -
resource tags
arch:x64arch:x86image:win7-20240611-enlocale:en-usos:windows7-x64system -
submitted
01-07-2024 02:52
Behavioral task
behavioral1
Sample
2fe82fa958281e1e508c9fccb4b85af3255d7ba5c1e5c8c9b8ba9dfea4176e02_NeikiAnalytics.pdf
Resource
win7-20240611-en
Behavioral task
behavioral2
Sample
2fe82fa958281e1e508c9fccb4b85af3255d7ba5c1e5c8c9b8ba9dfea4176e02_NeikiAnalytics.pdf
Resource
win10v2004-20240508-en
General
-
Target
2fe82fa958281e1e508c9fccb4b85af3255d7ba5c1e5c8c9b8ba9dfea4176e02_NeikiAnalytics.pdf
-
Size
45KB
-
MD5
369b0bb62ab5f502c140ea4f35ad9d80
-
SHA1
9ad7d094917a4c0f344f4221d1026e0d2f5553be
-
SHA256
2fe82fa958281e1e508c9fccb4b85af3255d7ba5c1e5c8c9b8ba9dfea4176e02
-
SHA512
81929c2d2282e13a889876cc585ea9f5949a4aead53597d3a88d03e9101095face4a21eebc98ffcaf8ab5a5125a9b1d0e9e9545eda6e39ac2a442b46dbc4563c
-
SSDEEP
768:GhZ458aE2pn3mhfcwNGDzqz9K0NW+Pts/PzrU1piCTB3u:OZ3aE83gESGizI0U/mTTFu
Malware Config
Signatures
-
Suspicious behavior: GetForegroundWindowSpam 1 IoCs
Processes:
AcroRd32.exepid process 2092 AcroRd32.exe -
Suspicious use of SetWindowsHookEx 4 IoCs
Processes:
AcroRd32.exepid process 2092 AcroRd32.exe 2092 AcroRd32.exe 2092 AcroRd32.exe 2092 AcroRd32.exe
Processes
-
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe"C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe" "C:\Users\Admin\AppData\Local\Temp\2fe82fa958281e1e508c9fccb4b85af3255d7ba5c1e5c8c9b8ba9dfea4176e02_NeikiAnalytics.pdf"1⤵
- Suspicious behavior: GetForegroundWindowSpam
- Suspicious use of SetWindowsHookEx
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Users\Admin\AppData\Roaming\Adobe\Acrobat\9.0\SharedDataEventsFilesize
3KB
MD574e233398c9bc5f570aec7d321be05b9
SHA159b0a78007eb2034466f2ebfebcdedaa74e0ec0c
SHA256049daeab4c9667aea816db4a6f28758c129a85a11773933771b13301f728206d
SHA512fc9bb9443040d55e7d5ddb8efa404aa1634197ad64b3e17f12f795dfc5203664ba34918531a3053fc7aa0a4dccacd642b30f2284dce5cdc9ce697a9e414f51f3