Analysis

  • max time kernel
    150s
  • max time network
    122s
  • platform
    windows7_x64
  • resource
    win7-20240508-en
  • resource tags

    arch:x64arch:x86image:win7-20240508-enlocale:en-usos:windows7-x64system
  • submitted
    01-07-2024 03:18

General

  • Target

    3177afbe1b57a48e5339ea5ff2c1a91b1614416eb9f277e40edaf677466c08f6_NeikiAnalytics.exe

  • Size

    57KB

  • MD5

    374706074681a360f6890983e8431650

  • SHA1

    135e9284620175748a99e3cd89fd6eb17c7698c6

  • SHA256

    3177afbe1b57a48e5339ea5ff2c1a91b1614416eb9f277e40edaf677466c08f6

  • SHA512

    27d7b02b4f8c0224c818693b2265df8e515e4f316ae32a4e1325d8bef0893816b5d3c42b65c6fb96bdf9a09ea3eb05f962dbbb39fa4c595618e3e3e870dafbf1

  • SSDEEP

    768:W7BlpppARFbhbt7Y7zPhwyPhwdOwOWF/MF/bnCvX108S3ZCvX108S3G:W7ZppApIayan2T81m3a1m3G

Score
9/10

Malware Config

Signatures

  • Renames multiple (3613) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\3177afbe1b57a48e5339ea5ff2c1a91b1614416eb9f277e40edaf677466c08f6_NeikiAnalytics.exe
    "C:\Users\Admin\AppData\Local\Temp\3177afbe1b57a48e5339ea5ff2c1a91b1614416eb9f277e40edaf677466c08f6_NeikiAnalytics.exe"
    1⤵
    • Drops file in Program Files directory
    PID:2104

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-2737914667-933161113-3798636211-1000\desktop.ini.tmp
    Filesize

    58KB

    MD5

    325e0292974db01af0581156580e1ef9

    SHA1

    ee2314264f17de28f557f807f4737000f355a06c

    SHA256

    c7bec7c89825720d8d1d4cd29037c466e0fd0c61f4c923317698513dee8840a2

    SHA512

    3cbf3a1216520d84a17332661cebe89c92ff125c42276615f59489d20da09a26145b923fb25a740421f1f51df894ed968776f7cd03034475910c7992c27fe117

  • C:\MSOCache\All Users\{90140000-0011-0000-0000-0000000FF1CE}-C\Office64WW.xml.tmp
    Filesize

    66KB

    MD5

    2fc517952fb97d6455b04cdfef7ad66b

    SHA1

    8fa2541a344f3e0d5bbb2af32ba81072ba8b8415

    SHA256

    66002672a29521b3acffe0b3178692626df0ad40f5514b1d971307ca6ef8b6dc

    SHA512

    261f80b4e9c61b882e5b34f6db975e0db582fffad2af35567201c6a9e96f3c4a2531075d618583e8e441c2431228c70a646f2712e6355144331bd8736bbc0e3b