Analysis

  • max time kernel
    124s
  • max time network
    119s
  • platform
    windows7_x64
  • resource
    win7-20240508-en
  • resource tags

    arch:x64arch:x86image:win7-20240508-enlocale:en-usos:windows7-x64system
  • submitted
    01-07-2024 03:58

General

  • Target

    33a13c709b8c2bcb8f03d10f39bbe25a46ff74825c01470db0135e1da6920b52_NeikiAnalytics.exe

  • Size

    46KB

  • MD5

    fca6fba96ffd93021b6b758a9e970250

  • SHA1

    88c94d758b2d7f1070f4d3158ec82ab8f7ef7510

  • SHA256

    33a13c709b8c2bcb8f03d10f39bbe25a46ff74825c01470db0135e1da6920b52

  • SHA512

    b339888ddccaafcc84d8e107639ee58600417ea23a714cfa0fc2112044df1fcf40c7d76f88bb1ecac37b7e12d0ae0bd7598d4900431f40b14deb00c2fd36164f

  • SSDEEP

    768:W7BlpppARFbhbt7Y7FoICOiJfoICOiJQ444ZqcjXY/IjXY/rL7:W7ZppApWmjXWY/IY/r

Score
9/10

Malware Config

Signatures

  • Renames multiple (3426) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\33a13c709b8c2bcb8f03d10f39bbe25a46ff74825c01470db0135e1da6920b52_NeikiAnalytics.exe
    "C:\Users\Admin\AppData\Local\Temp\33a13c709b8c2bcb8f03d10f39bbe25a46ff74825c01470db0135e1da6920b52_NeikiAnalytics.exe"
    1⤵
    • Drops file in Program Files directory
    PID:2556

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-2737914667-933161113-3798636211-1000\desktop.ini.tmp
    Filesize

    46KB

    MD5

    94b2a32d210028502837a0e5c78fb33d

    SHA1

    3bca429c0a33f264e07eb5786bd0baa2a6fbd476

    SHA256

    a96ef30702bdb0f60c7b3f86fa7aefd621e4a7037c12d46e66ff6232a0c94b7d

    SHA512

    f6f5b4ce21a7cd91999e142447367e3075b8a1667b0a7f88216bcb19e4df5a5202ec42ea8b685b4e41d9ba97f0dcbdce60d530768c416d9bd1532ab34bcb9a97

  • C:\MSOCache\All Users\{90140000-0011-0000-0000-0000000FF1CE}-C\Office64WW.xml.tmp
    Filesize

    55KB

    MD5

    6b0a47611c78d15b858d5a8950140072

    SHA1

    6541fc52a2b6d4c0428f477b0c5215d1f7bbd4b2

    SHA256

    9909943bb251eba5f9ee31cdaefb5dba7cbe256e4c263d9897a61d7f081e05d9

    SHA512

    0698c227b0187278283e250df2963082c99c4adf6abb0836c4ff523491449d0fe32113252640d1fd77c76b47bac516e543c585fb6f1073008a3be37760f6d25a