Analysis

  • max time kernel
    147s
  • max time network
    151s
  • platform
    windows10-2004_x64
  • resource
    win10v2004-20240508-en
  • resource tags

    arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system
  • submitted
    01-07-2024 03:50

General

  • Target

    334e4867a327eb5df421cc14ec3f98ff8d93d8f4aeafe870b0f80c283f9ec2ce_NeikiAnalytics.exe

  • Size

    55KB

  • MD5

    82efca0e8979c7121d04e1b32f48f380

  • SHA1

    e0e21ef908baffd03b5800fa96ebcd3ab196068e

  • SHA256

    334e4867a327eb5df421cc14ec3f98ff8d93d8f4aeafe870b0f80c283f9ec2ce

  • SHA512

    796b21ca2b2af3aac158b06e2eb1c977921c3bd73b2ec99074fb77902c2567dfee4a8c23ce085a9e23c51a7f8ad91c94488a548dbfe7584cef7bf68a5cdf2d0b

  • SSDEEP

    768:W7BlpppARFbhbt7Y7zPhwyPhwdOwOWF/MF/fweJtv/bt9G2XO2XJPu:W7ZppApIayan2O

Score
9/10

Malware Config

Signatures

  • Renames multiple (5196) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\334e4867a327eb5df421cc14ec3f98ff8d93d8f4aeafe870b0f80c283f9ec2ce_NeikiAnalytics.exe
    "C:\Users\Admin\AppData\Local\Temp\334e4867a327eb5df421cc14ec3f98ff8d93d8f4aeafe870b0f80c283f9ec2ce_NeikiAnalytics.exe"
    1⤵
    • Drops file in Program Files directory
    PID:2196

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-1337824034-2731376981-3755436523-1000\desktop.ini.tmp
    Filesize

    56KB

    MD5

    82e7d343b0b22cbf65045317bc6e2bd3

    SHA1

    4333e1055a443561baacd892554199834b753cbf

    SHA256

    2b0e03de269465b2c96063d6c69d03f7f57a43999588df6a5d82ef1471653664

    SHA512

    45615eddc5a8d22a52d39a88a8257337aeb5d3a381acfd17a529ba97438449aacca5e010a0a23f06e839b18707baabd2c9bf9ba8bb0f84bd343874ea56a70fee

  • C:\Program Files\7-Zip\7-zip.dll.tmp
    Filesize

    155KB

    MD5

    0a959d45827d97942b913936f13e771d

    SHA1

    10da4e2cc72c8df9c495130d6edd1bb88a2ca7b1

    SHA256

    ba75e406748442b5067ea2dca2d1242d28aacb6b0abef6db259d5d8543d34c54

    SHA512

    abf14dc6fb511600666d605f60dafda2d283db71a63f2183e1f724f2d7fa4a833207b08b30f0ce191fbbd8e8b8c9597ef28bc9c00590b95036ca991bdec38e6d