Analysis
-
max time kernel
122s -
max time network
128s -
platform
windows7_x64 -
resource
win7-20240508-en -
resource tags
arch:x64arch:x86image:win7-20240508-enlocale:en-usos:windows7-x64system -
submitted
01-07-2024 03:11
Behavioral task
behavioral1
Sample
311b2e828bc27f484561386bf866e9ee8debf45d2d350e61509d5d91587c5428_NeikiAnalytics.pdf
Resource
win7-20240508-en
Behavioral task
behavioral2
Sample
311b2e828bc27f484561386bf866e9ee8debf45d2d350e61509d5d91587c5428_NeikiAnalytics.pdf
Resource
win10v2004-20240508-en
General
-
Target
311b2e828bc27f484561386bf866e9ee8debf45d2d350e61509d5d91587c5428_NeikiAnalytics.pdf
-
Size
309KB
-
MD5
ca0b554cd04a35bcb3c1a8d9cc4ed600
-
SHA1
fd1aadcfbd7185aee93cd39150401c6792c8485f
-
SHA256
311b2e828bc27f484561386bf866e9ee8debf45d2d350e61509d5d91587c5428
-
SHA512
96b00a14a4f23e96c634249592ac3bd40ff5c01822013475c68845781eebde0dfba03a73f75556f492fd1c7308c6e9d4e980f07ff43288914a48e4fa2d7eabd4
-
SSDEEP
6144:YJ+XlL+JvuRLXGobRlvBukay5/cCYHQKHzgd3miUteyerAiBjkI:dL+J2ZXFufy5/czwKHzgMFyAiBjkI
Malware Config
Signatures
-
Suspicious behavior: GetForegroundWindowSpam 1 IoCs
Processes:
AcroRd32.exepid process 2972 AcroRd32.exe -
Suspicious use of SetWindowsHookEx 3 IoCs
Processes:
AcroRd32.exepid process 2972 AcroRd32.exe 2972 AcroRd32.exe 2972 AcroRd32.exe
Processes
-
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe"C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe" "C:\Users\Admin\AppData\Local\Temp\311b2e828bc27f484561386bf866e9ee8debf45d2d350e61509d5d91587c5428_NeikiAnalytics.pdf"1⤵
- Suspicious behavior: GetForegroundWindowSpam
- Suspicious use of SetWindowsHookEx
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Users\Admin\AppData\Roaming\Adobe\Acrobat\9.0\SharedDataEventsFilesize
3KB
MD56c225e9a49fd7ada890e12960bee5dab
SHA1c55f785c52c731dbe18a9cff62b8f3015ab99220
SHA25625137a84c1af307ceebe91dcd0f6c4d250b726b64b42732f400dbdc5261c2122
SHA512b388d93e87b8b9f00d4a9bb819055dad888cba7b759705578beb173a8c5810b22e098dd543d0759cf5d261f12f1de1c47e15de18dba1a70f301df02533ee28ca