Analysis
-
max time kernel
73s -
max time network
152s -
platform
windows10-2004_x64 -
resource
win10v2004-20240508-en -
resource tags
arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system -
submitted
01-07-2024 03:49
Static task
static1
Behavioral task
behavioral1
Sample
333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe
Resource
win7-20240508-en
Behavioral task
behavioral2
Sample
333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe
Resource
win10v2004-20240508-en
General
-
Target
333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe
-
Size
37KB
-
MD5
79e95a0594c2d4a042132fb469fce3c0
-
SHA1
4d05da6972beb4517f4eecf50b82ccb54e9328f7
-
SHA256
333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e
-
SHA512
018f5f99e1a941b80d6e8d066354c2f30ecb4529059a40da33b0b9450a6741c063bf7ef458723d1cc7285d0876aca945ee9fe1ca75fde5bacb3bce95827ecd85
-
SSDEEP
384:GBt7Br5xjL9AgA71FbhvuNBN2TQ1nrSLmnsNw/NwLux:W7BlpppARFbhknrSLmsNw/Nwy
Malware Config
Signatures
-
Renames multiple (1994) files with added filename extension
This suggests ransomware activity of encrypting all the files on the system.
-
Drops file in Program Files directory 64 IoCs
Processes:
333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exedescription ioc process File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\7.0.16\cs\System.Xaml.resources.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ink\pt-PT\tipresx.dll.mui.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\Source Engine\OSE.EXE.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.2\Microsoft.VisualBasic.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\8.0.2\fr\PresentationUI.resources.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.NETCore.App\7.0.16\System.Reflection.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.27\api-ms-win-core-console-l1-2-0.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\7.0.16\de\PresentationUI.resources.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\7.0.16\fr\UIAutomationTypes.resources.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\7.0.16\it\System.Windows.Forms.Primitives.resources.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\8.0.2\wpfgfx_cor3.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\6.0.27\pl\PresentationFramework.resources.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\7.0.16\es\System.Windows.Forms.Primitives.resources.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\8.0.2\pl\System.Windows.Forms.Design.resources.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\Common Files\System\ado\msado27.tlb.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\6.0.27\de\System.Xaml.resources.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\8.0.2\cs\Microsoft.VisualBasic.Forms.resources.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\Java\jdk-1.8\bin\vcruntime140.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ClickToRun\InspectorOfficeGadget.exe.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.NETCore.App\7.0.16\System.Threading.ThreadPool.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.2\System.Reflection.Emit.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\6.0.27\pt-BR\WindowsBase.resources.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\7-Zip\Lang\gu.txt.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\host\fxr\6.0.27\hostfxr.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.27\System.Reflection.Extensions.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\7.0.16\es\System.Windows.Input.Manipulations.resources.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\8.0.2\ja\System.Windows.Forms.Design.resources.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ink\hwrenclm.dat.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\LICENSE.txt.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\6.0.27\cs\System.Windows.Forms.resources.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\7.0.16\es\System.Xaml.resources.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\7.0.16\fr\System.Windows.Forms.resources.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\oskpred.xml.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ink\hwrusash.dat.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\6.0.27\ru\UIAutomationClient.resources.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\7.0.16\ru\PresentationCore.resources.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ink\et-EE\tipresx.dll.mui.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.27\System.Private.Uri.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.NETCore.App\7.0.16\System.Security.Cryptography.OpenSsl.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\6.0.27\ru\System.Windows.Forms.Primitives.resources.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\7.0.16\ru\ReachFramework.resources.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\Java\jdk-1.8\bin\api-ms-win-core-handle-l1-1-0.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.27\createdump.exe.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.27\System.Net.NameResolution.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\7.0.16\System.Drawing.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\8.0.2\PresentationFramework.AeroLite.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\Google\Chrome\Application\110.0.5481.104\Locales\he.pak.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\Java\jdk-1.8\bin\msvcp140.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\Java\jdk-1.8\jre\bin\api-ms-win-core-datetime-l1-1-0.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\6.0.27\cs\System.Windows.Forms.Primitives.resources.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\6.0.27\es\Microsoft.VisualBasic.Forms.resources.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\6.0.27\ko\UIAutomationClient.resources.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\6.0.27\pl\ReachFramework.resources.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\8.0.2\PresentationFramework.Aero.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\8.0.2\zh-Hans\UIAutomationTypes.resources.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\Google\Chrome\Application\110.0.5481.104\Locales\sk.pak.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\Java\jdk-1.8\bin\jrunscript.exe.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ink\ja-JP\TipTsf.dll.mui.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\6.0.27\pl\WindowsFormsIntegration.resources.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\6.0.27\zh-Hant\UIAutomationClient.resources.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\6.0.27\zh-Hant\WindowsBase.resources.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\8.0.2\de\System.Windows.Forms.Primitives.resources.dll.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ink\ipshrv.xml.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe File created C:\Program Files\Common Files\System\ado\msado20.tlb.tmp 333df0eb9a02b1c79f286449b3ec8ea00b97502a8821bbec6a79add726d7947e_NeikiAnalytics.exe
Processes
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\$Recycle.Bin\S-1-5-21-4124900551-4068476067-3491212533-1000\desktop.ini.tmpFilesize
37KB
MD5ea121e22c9b1830cdd1dc4273a50a2d3
SHA1cefd44403bf0365b9a956d850a5087cdaa62d63a
SHA2568c419aeca94ef3390d7a6bfc79f636221cac66e2dddea002af3588dd4c2c845d
SHA512e7275db2ef9b8d0e6b080260d11973a161f31b98e2f0afadef52d15b1b73e8214c7ced7099c6838d83d59c2bd02d0996c829161bfe53c59e22d41aabf4ca4da2
-
C:\Program Files\7-Zip\7-zip.dll.tmpFilesize
136KB
MD58e257291c3a62fe1870ac331857431f4
SHA1bbb152d8d9511d23de935c82082bc24ceb79a29e
SHA256ea67f12a43bf67ee5276b6babfac640465effcafd11efe522b19d6f43b3ac6ec
SHA5127b21317988012c7335935dc8cc90ed99930e1d77cecfc57d066cb51b5795b3ed2cde77871b74107b34b9e2171039676d8f571f05e779b6b755e7dd009fdd961e