Analysis
-
max time kernel
120s -
max time network
121s -
platform
windows7_x64 -
resource
win7-20240508-en -
resource tags
arch:x64arch:x86image:win7-20240508-enlocale:en-usos:windows7-x64system -
submitted
01-07-2024 03:47
Behavioral task
behavioral1
Sample
332728b701eff4ce368aae09b8255a9b0ed875965284fabd81ec6386c0445824_NeikiAnalytics.pdf
Resource
win7-20240508-en
Behavioral task
behavioral2
Sample
332728b701eff4ce368aae09b8255a9b0ed875965284fabd81ec6386c0445824_NeikiAnalytics.pdf
Resource
win10v2004-20240611-en
General
-
Target
332728b701eff4ce368aae09b8255a9b0ed875965284fabd81ec6386c0445824_NeikiAnalytics.pdf
-
Size
138KB
-
MD5
438374a752463c10d2cfd8d18ffe1fa0
-
SHA1
c347b76806bf607e4b73fb9e32ca3a6d3b8f09cc
-
SHA256
332728b701eff4ce368aae09b8255a9b0ed875965284fabd81ec6386c0445824
-
SHA512
51cffa009bdd1f3a04472b49df082d215727075f8d28b1316d11830f375b2831ef796afa9ddd0d41441ae5ba2021de25c6993a86a2253dd4956e94c0800cc709
-
SSDEEP
3072:CrWfPi56CLq0PahjnvBmH7mvUjZmfkQ+ozHa4:COPXIKjnvB+mFfknoz/
Malware Config
Signatures
-
Suspicious behavior: GetForegroundWindowSpam 1 IoCs
Processes:
AcroRd32.exepid process 1848 AcroRd32.exe -
Suspicious use of SetWindowsHookEx 3 IoCs
Processes:
AcroRd32.exepid process 1848 AcroRd32.exe 1848 AcroRd32.exe 1848 AcroRd32.exe
Processes
-
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe"C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe" "C:\Users\Admin\AppData\Local\Temp\332728b701eff4ce368aae09b8255a9b0ed875965284fabd81ec6386c0445824_NeikiAnalytics.pdf"1⤵
- Suspicious behavior: GetForegroundWindowSpam
- Suspicious use of SetWindowsHookEx
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Users\Admin\AppData\Roaming\Adobe\Acrobat\9.0\SharedDataEventsFilesize
3KB
MD5f1a157d39e42621e443c2cc49b28dddf
SHA192c36ded8e790c1cc288ddc6628c2741dd57e035
SHA256e98c7ab0ff7350133350ac9b06afbee2c3ddad767549ddca70689a560739129c
SHA5123d7a3007a1313b0914fcf72de44acb4b13c16f095b8d546dfdfec8b1b207c8d2df8bae509de9b44bf5cf2d56efd1376c12a65ee2ba6ef8edaf063fedfa443412