Analysis

  • max time kernel
    150s
  • max time network
    119s
  • platform
    windows7_x64
  • resource
    win7-20240508-en
  • resource tags

    arch:x64arch:x86image:win7-20240508-enlocale:en-usos:windows7-x64system
  • submitted
    01-07-2024 03:53

General

  • Target

    336697b398d329aec6f555e22a416b62135595acbf0081cbf0c13b91c81d0c87_NeikiAnalytics.exe

  • Size

    91KB

  • MD5

    f077b635a07070b58a6088bfab2e0960

  • SHA1

    2e1f88a397c510a68a3bb24fb21c5b0b4792f7ec

  • SHA256

    336697b398d329aec6f555e22a416b62135595acbf0081cbf0c13b91c81d0c87

  • SHA512

    69467f134278abdf477b2b9703d15f3e5b388a2be167e8f45ac3d182b19d759536dd65895d1b0d73a3d36afd48307756b4825587ae8bd781601e065fc0e282c3

  • SSDEEP

    1536:W7ZhA7pApMaxB4b0CYJ97lEVqNR7Yge+eJG/x/OfxRfxHAu39Au3J:6e7WpMaxeb0CYJ97lEYNR73e+eKZOf7p

Score
9/10

Malware Config

Signatures

  • Renames multiple (2937) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\336697b398d329aec6f555e22a416b62135595acbf0081cbf0c13b91c81d0c87_NeikiAnalytics.exe
    "C:\Users\Admin\AppData\Local\Temp\336697b398d329aec6f555e22a416b62135595acbf0081cbf0c13b91c81d0c87_NeikiAnalytics.exe"
    1⤵
    • Drops file in Program Files directory
    PID:1744

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-268080393-3149932598-1824759070-1000\desktop.ini.tmp
    Filesize

    91KB

    MD5

    f11c808df745aab78847b7d1dbe0228b

    SHA1

    ae861aa3f2afbf56fc7a0cdfd3cdbc90107de199

    SHA256

    8a9941aa8eb04e8f710116a76924c6f2fe66c18981fe3d5e38695de4ac4a58a8

    SHA512

    9db9b030e22f0a1603189a1f8141e9c5c39cf1099bcd5ff9074c0ec8b1fbaee8ba290d4fed205e1c90b53ff60a4bdd0c190d6835a462a05a901dcbf9c9fbc5d5

  • C:\MSOCache\All Users\{90140000-0011-0000-0000-0000000FF1CE}-C\Office64WW.xml.tmp
    Filesize

    100KB

    MD5

    11737a746619f8b33d59a852bcccc413

    SHA1

    b0fd4ef7c1d306240ff1ef6e81f0871924ff82a7

    SHA256

    dbe1889b837b3bb9d8fb5a5190ae02979bdf472e6c48ead78d850452bd36233a

    SHA512

    647719d2e37b26ef77455c69c310ae574359fe4388c69c7654f7f3ae693721b6c9d637561c9bfdfb0dd2b266c65b58aa1372aa1525338a657474b3be68437822