Analysis

  • max time kernel
    150s
  • max time network
    110s
  • platform
    windows10-2004_x64
  • resource
    win10v2004-20240611-en
  • resource tags

    arch:x64arch:x86image:win10v2004-20240611-enlocale:en-usos:windows10-2004-x64system
  • submitted
    01-07-2024 03:57

General

  • Target

    3398f04df4a4b2438efa815f265d65908349c92f68d776168bef9e7eeb1b219d_NeikiAnalytics.exe

  • Size

    81KB

  • MD5

    26581b429795353c5d0ea4e653d3a540

  • SHA1

    2620125013c42fbc661b0413330fb8f27635f96f

  • SHA256

    3398f04df4a4b2438efa815f265d65908349c92f68d776168bef9e7eeb1b219d

  • SHA512

    02e13ab65af1123981fbfca596c9ea1f80c5e7dfa98ef754b7bef78cbd61666a00d0d461498338624f74c08b0cbb9a995ddd8b6d50d97c546ce7035d228831c2

  • SSDEEP

    768:W7BlpDpARFbhYQkQjjIXYvPXzWPXzK3733uF4V7en5c5HChCrmh1444REXBwzEXT:W7ZDpApYbWjIoPyPoLzV7c6Sh1XB

Score
9/10

Malware Config

Signatures

  • Renames multiple (4657) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\3398f04df4a4b2438efa815f265d65908349c92f68d776168bef9e7eeb1b219d_NeikiAnalytics.exe
    "C:\Users\Admin\AppData\Local\Temp\3398f04df4a4b2438efa815f265d65908349c92f68d776168bef9e7eeb1b219d_NeikiAnalytics.exe"
    1⤵
    • Drops file in Program Files directory
    PID:1740

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-2447855248-390457009-3660902674-1000\desktop.ini.tmp
    Filesize

    81KB

    MD5

    fd8921064a85d6b86ce22677f79784d6

    SHA1

    d4e1cf3069860d8ab17dfa8b04dc4e48d7f7961e

    SHA256

    629d432e29c23d25c7b64f6ee5f61daf9bbccef8d09cbc5162f58efb48b27429

    SHA512

    37ddba3ff6d4ea8437b442d22c7a9793cae6f20674edf955e8f0818ed406542ca29bde233b550fb8252efba4cd5195638a3eeb13fb0e07b9be1d7006f57cc1d0

  • C:\Program Files\7-Zip\7-zip.dll.tmp
    Filesize

    180KB

    MD5

    c18368e983da4c480c0d00337fda98ec

    SHA1

    0ba60bc4f643390979859a73247e7559db56a5b6

    SHA256

    dcf0ad6341e67a6de2353d20e74056fd17d815d08f73dd1db7732aa9ed6e8a7c

    SHA512

    47e4fa7ac2fc0fbef00c51e86754e844f7b8a0bcfbaae13444fc4194a45ad031422d4a9ba5e0ec33260c7a19daad99d42ef0afe86c7a22c2783fb83585cb3328