Analysis

  • max time kernel
    150s
  • max time network
    124s
  • platform
    windows7_x64
  • resource
    win7-20240221-en
  • resource tags

    arch:x64arch:x86image:win7-20240221-enlocale:en-usos:windows7-x64system
  • submitted
    01-07-2024 03:50

General

  • Target

    334e4867a327eb5df421cc14ec3f98ff8d93d8f4aeafe870b0f80c283f9ec2ce_NeikiAnalytics.exe

  • Size

    55KB

  • MD5

    82efca0e8979c7121d04e1b32f48f380

  • SHA1

    e0e21ef908baffd03b5800fa96ebcd3ab196068e

  • SHA256

    334e4867a327eb5df421cc14ec3f98ff8d93d8f4aeafe870b0f80c283f9ec2ce

  • SHA512

    796b21ca2b2af3aac158b06e2eb1c977921c3bd73b2ec99074fb77902c2567dfee4a8c23ce085a9e23c51a7f8ad91c94488a548dbfe7584cef7bf68a5cdf2d0b

  • SSDEEP

    768:W7BlpppARFbhbt7Y7zPhwyPhwdOwOWF/MF/fweJtv/bt9G2XO2XJPu:W7ZppApIayan2O

Score
9/10

Malware Config

Signatures

  • Renames multiple (3433) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\334e4867a327eb5df421cc14ec3f98ff8d93d8f4aeafe870b0f80c283f9ec2ce_NeikiAnalytics.exe
    "C:\Users\Admin\AppData\Local\Temp\334e4867a327eb5df421cc14ec3f98ff8d93d8f4aeafe870b0f80c283f9ec2ce_NeikiAnalytics.exe"
    1⤵
    • Drops file in Program Files directory
    PID:340

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-2297530677-1229052932-2803917579-1000\desktop.ini.tmp
    Filesize

    56KB

    MD5

    e7c64ca4b8343a324bb238006aa1afcc

    SHA1

    c9b5c396dc7e9f3ecfd1ddeb911ff05c9667a0a1

    SHA256

    342a6ed97eb02ff8ae0aaf4e650ca4e3af51d3c82ed1d7700556fb1c8e555a4b

    SHA512

    b58c86dfeb4eb7d3d0cc29c29282d6bf699e12133178d91a74158a399b31a19151189c2d55be55800acfae39aa29f211f5e18ef5cff1df2f8fc43bf29de532d0

  • C:\MSOCache\All Users\{90140000-0011-0000-0000-0000000FF1CE}-C\Office64WW.xml.tmp
    Filesize

    65KB

    MD5

    8e0084bf06e53ab5c30a8a897647b839

    SHA1

    a230fc51b1739ad682bfc997b284c3128bf15216

    SHA256

    b5d0c221011711a0d9cde9a37f90d4274a607d7600f9a47443ca86a97079c86e

    SHA512

    3a40f5f0bfef729169669fac0e8e664b27b3f8f72cfd34b5c4e86fac037c13f5871216a0750769eb711c17df957888f3fd63c53b6603d4d5f53ec8214389524a