Analysis

  • max time kernel
    150s
  • max time network
    152s
  • platform
    windows10-2004_x64
  • resource
    win10v2004-20240611-en
  • resource tags

    arch:x64arch:x86image:win10v2004-20240611-enlocale:en-usos:windows10-2004-x64system
  • submitted
    01-07-2024 03:46

General

  • Target

    331d9ab0f6b9c74fced691f0e533bdc35b5e993ac1de7a002d2c4999a4da73f5_NeikiAnalytics.exe

  • Size

    38KB

  • MD5

    3f654599d7f06ef814abc936dccaea70

  • SHA1

    1069433ba3cdd3406abe348c3e17364039281931

  • SHA256

    331d9ab0f6b9c74fced691f0e533bdc35b5e993ac1de7a002d2c4999a4da73f5

  • SHA512

    5961403b03ba2561d101505c8fcd591c03aae7f82a71ef7e42a951c2f68cbefe71ad49ef689e929dc0d42e76cc152e1bf690ef55d16de4d9bc0d68cc7484a57f

  • SSDEEP

    384:GBt7Br5xjL9AgA71FbhvuNBN2TqXSg4vm3lXSg4vm3JF0FM:W7BlpppARFbhaKM

Score
9/10

Malware Config

Signatures

  • Renames multiple (4823) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\331d9ab0f6b9c74fced691f0e533bdc35b5e993ac1de7a002d2c4999a4da73f5_NeikiAnalytics.exe
    "C:\Users\Admin\AppData\Local\Temp\331d9ab0f6b9c74fced691f0e533bdc35b5e993ac1de7a002d2c4999a4da73f5_NeikiAnalytics.exe"
    1⤵
    • Drops file in Program Files directory
    PID:320

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-4204450073-1267028356-951339405-1000\desktop.ini.tmp
    Filesize

    39KB

    MD5

    7a154cbffcb2ccee14a885e673e6410a

    SHA1

    18c37667c314bd329d74f34addb1e2242cb314f4

    SHA256

    bb775a12b2dee5d28ac2b9056f7529c924e0ebb8b994ba61ed4e0810051d1353

    SHA512

    8131ca902b4bc1fdc05247b2f1fa84074c6acfd18210aacbb6c893076c026a699915f84ab2b818688b422b11f747cd29d751863788eac22751a2a6cf4149d534

  • C:\Program Files\7-Zip\7-zip.dll.tmp
    Filesize

    138KB

    MD5

    dbdf55a68342a8344072d59b4c81d40a

    SHA1

    4f04a953269ffd0db73310ce27fdef0025b66b1c

    SHA256

    0c5a91e31150e87a3a4619cbee432ab80427e4d3b4c85725c6736db2428c9bc7

    SHA512

    1129b5fa85278f654abb3dcbbb733d09650c233954efaace8f97e5ec8670f9a3fcb0fa28161c62d34d813a8b32bf7c9b39306f8a7b517edbd1e98e7e3db2f1f9