Analysis

  • max time kernel
    114s
  • max time network
    49s
  • platform
    windows10-2004_x64
  • resource
    win10v2004-20240508-en
  • resource tags

    arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system
  • submitted
    01-07-2024 03:23

General

  • Target

    31ce68cc39645f80f48781083ba9d2baa6e23a94344366c479994fa83a891ba0_NeikiAnalytics.exe

  • Size

    40KB

  • MD5

    c8fc5f98eb277d58e9f467cb1bb5ba80

  • SHA1

    1db5bcfebd74760ee8896c23821b99e09ef11dcf

  • SHA256

    31ce68cc39645f80f48781083ba9d2baa6e23a94344366c479994fa83a891ba0

  • SHA512

    e4138dfab8710646f798ed21adc776653c548580175b52b5015f92a67c932da714e302ef9429a04ab86a7faf7d306e4f0037392694089fc5a0731e38aab2d964

  • SSDEEP

    384:GBt7Br5xjL9AgA71FbhvuNBN1qmq4Gqmq4MAAAJOQAAAJOo:W7BlpppARFbhwEnAAJ+AAJJ

Score
9/10

Malware Config

Signatures

  • Renames multiple (4374) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\31ce68cc39645f80f48781083ba9d2baa6e23a94344366c479994fa83a891ba0_NeikiAnalytics.exe
    "C:\Users\Admin\AppData\Local\Temp\31ce68cc39645f80f48781083ba9d2baa6e23a94344366c479994fa83a891ba0_NeikiAnalytics.exe"
    1⤵
    • Drops file in Program Files directory
    PID:1360

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-1337824034-2731376981-3755436523-1000\desktop.ini.tmp
    Filesize

    40KB

    MD5

    16fa606c5dc03c3ec2d99676dd4e8aca

    SHA1

    39705de089f1491f049d876b4dc60d3bbf91985e

    SHA256

    e984db5acfdae581dcfeb141c284d5eefd0f00dfcf13071ccbf0637f4efb2724

    SHA512

    0f85e6e44928453d32993c26afbca5567a46309c7e8bfff58017bde7e4e1c7efffd2657bba916b38c817897aa1bd13a5ded5b9bc1e998d763f0009489713fe33

  • C:\Program Files\7-Zip\7-zip.dll.tmp
    Filesize

    139KB

    MD5

    0f65873a499f864c1575fb3bbd370b72

    SHA1

    8926d78a425c0ae1ee807fcb86e54a2b1cecbeb2

    SHA256

    ab391ea0039a6ce37033d46c52652ed7fa918400d170a870c291e3ba13b1ae39

    SHA512

    ae68545ebddc10c011e16beb00ef69e1a1f5917233b18eb72021905920b0676cdd227f92bdb666fbbc6e5c5b51ab694af0039e9d39ecfd178ea56b77442d366d