Analysis

  • max time kernel
    150s
  • max time network
    121s
  • platform
    windows7_x64
  • resource
    win7-20231129-en
  • resource tags

    arch:x64arch:x86image:win7-20231129-enlocale:en-usos:windows7-x64system
  • submitted
    01-07-2024 03:56

General

  • Target

    3386bc51d56d3b1efac1c47959f47b5ad853e92e049d098bd116de4a99a8accb_NeikiAnalytics.exe

  • Size

    83KB

  • MD5

    77773cb744ef106244a2949fb0648a90

  • SHA1

    2c496ba644abdea863872c61780c919fb1fe3b00

  • SHA256

    3386bc51d56d3b1efac1c47959f47b5ad853e92e049d098bd116de4a99a8accb

  • SHA512

    eb29143649186fde75cf02caa66da1c32cfc989df437f7d9d70a6423830b23b4c3205635273fcbcce406bdc720d563160df999f56663a75f8ad8507445409cbf

  • SSDEEP

    1536:W7Z9pApQESOHepOHe8G+6E65dyGdykNdNBK2LUO:69WpQE0zUO

Score
9/10

Malware Config

Signatures

  • Renames multiple (2851) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\3386bc51d56d3b1efac1c47959f47b5ad853e92e049d098bd116de4a99a8accb_NeikiAnalytics.exe
    "C:\Users\Admin\AppData\Local\Temp\3386bc51d56d3b1efac1c47959f47b5ad853e92e049d098bd116de4a99a8accb_NeikiAnalytics.exe"
    1⤵
    • Drops file in Program Files directory
    PID:1884

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-3627615824-4061627003-3019543961-1000\desktop.ini.tmp
    Filesize

    84KB

    MD5

    dfe237aa6b95fc637faec44beda07e9a

    SHA1

    c2160c8f5e9facb3ffce6b48823e2a2a4ff7b77d

    SHA256

    60fba537d517a8d42b420defa32d41b8554bb315bc4678061fb47932d5863d72

    SHA512

    302626930362b527a932324f1f6a37e22f2056b41be237f21c326db2d1f8f8438020bf842301c6750137cdbd4a0943c37ffed6634c03a32fdc8ac07308d5f6cb

  • C:\MSOCache\All Users\{90140000-0011-0000-0000-0000000FF1CE}-C\Office64WW.xml.tmp
    Filesize

    93KB

    MD5

    8dcf4ce3180f680855da52acf2cc013b

    SHA1

    70cfc4f54a41d979a257611467d0f1133c66bd16

    SHA256

    8529bec96748597485d136083100017ed6175a01d9dda2fa4a7ccc764049d597

    SHA512

    6dbd65b7b5f6e365db095b57d17b8a118a9d502f3cf514e9e3b6a80fce79aa5f5ef5fc267d774dcb93d6075ca4344f126a0d10eabb84a8c97b0344e42f47b463