Analysis

  • max time kernel
    110s
  • max time network
    47s
  • platform
    windows10-2004_x64
  • resource
    win10v2004-20240508-en
  • resource tags

    arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system
  • submitted
    01-07-2024 03:58

General

  • Target

    33a13c709b8c2bcb8f03d10f39bbe25a46ff74825c01470db0135e1da6920b52_NeikiAnalytics.exe

  • Size

    46KB

  • MD5

    fca6fba96ffd93021b6b758a9e970250

  • SHA1

    88c94d758b2d7f1070f4d3158ec82ab8f7ef7510

  • SHA256

    33a13c709b8c2bcb8f03d10f39bbe25a46ff74825c01470db0135e1da6920b52

  • SHA512

    b339888ddccaafcc84d8e107639ee58600417ea23a714cfa0fc2112044df1fcf40c7d76f88bb1ecac37b7e12d0ae0bd7598d4900431f40b14deb00c2fd36164f

  • SSDEEP

    768:W7BlpppARFbhbt7Y7FoICOiJfoICOiJQ444ZqcjXY/IjXY/rL7:W7ZppApWmjXWY/IY/r

Score
9/10

Malware Config

Signatures

  • Renames multiple (4437) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\33a13c709b8c2bcb8f03d10f39bbe25a46ff74825c01470db0135e1da6920b52_NeikiAnalytics.exe
    "C:\Users\Admin\AppData\Local\Temp\33a13c709b8c2bcb8f03d10f39bbe25a46ff74825c01470db0135e1da6920b52_NeikiAnalytics.exe"
    1⤵
    • Drops file in Program Files directory
    PID:792

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-1337824034-2731376981-3755436523-1000\desktop.ini.tmp
    Filesize

    46KB

    MD5

    50016de89383e9b81d28a921d4358a62

    SHA1

    c2e03570dd95633b5a01c458010ec19f86eaaf49

    SHA256

    b103eb5d4d7406fabb6fcd3f76b48ea593324d9a5898e09c54fce3d5331349eb

    SHA512

    10c16b1961753581b4f161f54778617e5a8234175d1e46b21eca5d41638949fa43b22a8f0c6e73195c466b848b31762a70c0801953892fec9e51aee8602b28a5

  • C:\Program Files\7-Zip\7-zip.dll.tmp
    Filesize

    145KB

    MD5

    464865e21ba26a3f36492e1ea004e66e

    SHA1

    8a0e0e1b309195a6bee269738635fbd1324ce3a8

    SHA256

    a4c4ed6a62c0efa7ac8f0c1dc8b764ee8fbf55ba64d9eb3137ac5018a96bf82d

    SHA512

    feff03f4ea5c1c193f9943942e99e1adc2af3a8c67920018ce9fe2dd238afad44503d07c7cdfa748c8bb47e39cdc4b31f4b447aa784a55b39c3f7aa998c4ea7a