Analysis

  • max time kernel
    123s
  • max time network
    118s
  • platform
    windows7_x64
  • resource
    win7-20240508-en
  • resource tags

    arch:x64arch:x86image:win7-20240508-enlocale:en-usos:windows7-x64system
  • submitted
    01-07-2024 03:46

General

  • Target

    331d9ab0f6b9c74fced691f0e533bdc35b5e993ac1de7a002d2c4999a4da73f5_NeikiAnalytics.exe

  • Size

    38KB

  • MD5

    3f654599d7f06ef814abc936dccaea70

  • SHA1

    1069433ba3cdd3406abe348c3e17364039281931

  • SHA256

    331d9ab0f6b9c74fced691f0e533bdc35b5e993ac1de7a002d2c4999a4da73f5

  • SHA512

    5961403b03ba2561d101505c8fcd591c03aae7f82a71ef7e42a951c2f68cbefe71ad49ef689e929dc0d42e76cc152e1bf690ef55d16de4d9bc0d68cc7484a57f

  • SSDEEP

    384:GBt7Br5xjL9AgA71FbhvuNBN2TqXSg4vm3lXSg4vm3JF0FM:W7BlpppARFbhaKM

Score
9/10

Malware Config

Signatures

  • Renames multiple (2846) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\331d9ab0f6b9c74fced691f0e533bdc35b5e993ac1de7a002d2c4999a4da73f5_NeikiAnalytics.exe
    "C:\Users\Admin\AppData\Local\Temp\331d9ab0f6b9c74fced691f0e533bdc35b5e993ac1de7a002d2c4999a4da73f5_NeikiAnalytics.exe"
    1⤵
    • Drops file in Program Files directory
    PID:2984

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-268080393-3149932598-1824759070-1000\desktop.ini.tmp
    Filesize

    39KB

    MD5

    694de9e7ab5fe1a1c0c042f5e0d05fd7

    SHA1

    7afee6d732bab7e196be259ccedf2739edb9cdcc

    SHA256

    3ddab0c56432e359199c62d3470d16a8738905ed594f95e00e38fbbe35cef25f

    SHA512

    13e55ac6b95ceace55d0d9b81851a5d3bc908caf2e01745fd48a083b13776b3bba36c05e001129d5b3e42e1a8e6be358e83e8158ff2ac83177828d43f7d9b657

  • C:\MSOCache\All Users\{90140000-0011-0000-0000-0000000FF1CE}-C\Office64WW.xml.tmp
    Filesize

    48KB

    MD5

    ca4e4f5de47fc74b46214c0eafa5f119

    SHA1

    795990be03c7c7dbba53ebdc394fb8a760cc90f4

    SHA256

    716e1e04ffbd202803a21581dabee9531c9700c0a91f37b4285376c935d26954

    SHA512

    e6b342dd23b4828ae5b422c5f1cccbdd454c9016bf87c210eeef21b370a23ced0d4ce56a01e7a92474f49f5fb25d55b4ac252b167459a2de1442d090663292f5