General

  • Target

    335e90f0f5b55752855cee88cba7dfa544773822226f6bcf317073101ccaf62e_NeikiAnalytics.exe

  • Size

    192KB

  • Sample

    240701-ee111svhkg

  • MD5

    81cb51189a03cd2d9c46db22a3aad1e0

  • SHA1

    25954507495885fdb7a1eaf92ec1399cfa0194b7

  • SHA256

    335e90f0f5b55752855cee88cba7dfa544773822226f6bcf317073101ccaf62e

  • SHA512

    203c4c9f849f94922f71ce885961ace882491540c5e16e9028d05e70903ed3977845b463e37c0e32af20287db70c2527e2589420cd94d7a1e0c0b0faddb7ce98

  • SSDEEP

    1536:V7Zf/FAxTWY1++PJHJXA/OsIZfzc3/Q8asUsJOVYd7n97ndJA/fqJA/fe7Zf/FA5:fnyiQSohsUsKY5ZtnyiQSohsUsKY5ZC

Score
9/10

Malware Config

Targets

    • Target

      335e90f0f5b55752855cee88cba7dfa544773822226f6bcf317073101ccaf62e_NeikiAnalytics.exe

    • Size

      192KB

    • MD5

      81cb51189a03cd2d9c46db22a3aad1e0

    • SHA1

      25954507495885fdb7a1eaf92ec1399cfa0194b7

    • SHA256

      335e90f0f5b55752855cee88cba7dfa544773822226f6bcf317073101ccaf62e

    • SHA512

      203c4c9f849f94922f71ce885961ace882491540c5e16e9028d05e70903ed3977845b463e37c0e32af20287db70c2527e2589420cd94d7a1e0c0b0faddb7ce98

    • SSDEEP

      1536:V7Zf/FAxTWY1++PJHJXA/OsIZfzc3/Q8asUsJOVYd7n97ndJA/fqJA/fe7Zf/FA5:fnyiQSohsUsKY5ZtnyiQSohsUsKY5ZC

    Score
    9/10
    • Renames multiple (198) files with added filename extension

      This suggests ransomware activity of encrypting all the files on the system.

    • Executes dropped EXE

    • Loads dropped DLL

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

    • Drops file in System32 directory

MITRE ATT&CK Matrix

Tasks