Analysis

  • max time kernel
    150s
  • max time network
    128s
  • platform
    windows7_x64
  • resource
    win7-20240221-en
  • resource tags

    arch:x64arch:x86image:win7-20240221-enlocale:en-usos:windows7-x64system
  • submitted
    01-07-2024 03:23

General

  • Target

    31ce68cc39645f80f48781083ba9d2baa6e23a94344366c479994fa83a891ba0_NeikiAnalytics.exe

  • Size

    40KB

  • MD5

    c8fc5f98eb277d58e9f467cb1bb5ba80

  • SHA1

    1db5bcfebd74760ee8896c23821b99e09ef11dcf

  • SHA256

    31ce68cc39645f80f48781083ba9d2baa6e23a94344366c479994fa83a891ba0

  • SHA512

    e4138dfab8710646f798ed21adc776653c548580175b52b5015f92a67c932da714e302ef9429a04ab86a7faf7d306e4f0037392694089fc5a0731e38aab2d964

  • SSDEEP

    384:GBt7Br5xjL9AgA71FbhvuNBN1qmq4Gqmq4MAAAJOQAAAJOo:W7BlpppARFbhwEnAAJ+AAJJ

Score
9/10

Malware Config

Signatures

  • Renames multiple (3451) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\31ce68cc39645f80f48781083ba9d2baa6e23a94344366c479994fa83a891ba0_NeikiAnalytics.exe
    "C:\Users\Admin\AppData\Local\Temp\31ce68cc39645f80f48781083ba9d2baa6e23a94344366c479994fa83a891ba0_NeikiAnalytics.exe"
    1⤵
    • Drops file in Program Files directory
    PID:2128

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-2297530677-1229052932-2803917579-1000\desktop.ini.tmp
    Filesize

    40KB

    MD5

    421c6ceb8a08b84c0c5502be247f419a

    SHA1

    1aeb546153f1c06af66a611f47c0497c74678242

    SHA256

    483017068f0fe44e49cbdd2cc6522dc9c62d4d81e16a09da9b7a8dc93ebc24a6

    SHA512

    39b8cd28603d96eb5789b888f9da4ed3722cf6cf6d8ae8fe5a58e70825cc67fb7aa387c299f98a21b5382ff8ba7972fa9a3284b02de633cbe4b3a52c860a1cb1

  • C:\MSOCache\All Users\{90140000-0011-0000-0000-0000000FF1CE}-C\Office64WW.xml.tmp
    Filesize

    49KB

    MD5

    5e480b2555ec9346c162254b2da15e25

    SHA1

    416d67251196727370505c5c4fc16ff60ccbd9e5

    SHA256

    6d1ddf7e508edb3b20ce1d9cb03b9ba164c7790e98b18dab48c8e196851c878e

    SHA512

    05ea03fa545477255c1b3cf700f4b2832f4432f403cb7a1b182c86bec78dcf87973cd7004e02a4ec1344e70162d95e03304c990a415ae519634af4ee5eb009f9