Analysis

  • max time kernel
    150s
  • max time network
    121s
  • platform
    windows7_x64
  • resource
    win7-20240611-en
  • resource tags

    arch:x64arch:x86image:win7-20240611-enlocale:en-usos:windows7-x64system
  • submitted
    01-07-2024 04:00

General

  • Target

    33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe

  • Size

    85KB

  • MD5

    57a51ac463ae8b49c3ce8fbaafa5d800

  • SHA1

    063a6ae99fa8725c9bfe41c195edfb33d688edcc

  • SHA256

    33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e

  • SHA512

    56834445e42b80a6cb83603b70f792b5e8af7e14f13812732bc20d8a3975823035a9f62d0cee129d3dd4894905ed673dadf66ff52c0c9b488eceb30b3a19942f

  • SSDEEP

    1536:W7ZhA7pApH1d9oVLQthbqbY9oVLQthbq51Rn6wt7t5m0m69YUpCUppXxXTXxXX:6e7WpP9oVLQthbYY9oVLQthbUrt7t5ma

Score
9/10

Malware Config

Signatures

  • Renames multiple (3107) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe
    "C:\Users\Admin\AppData\Local\Temp\33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe"
    1⤵
    • Drops file in Program Files directory
    PID:2016

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-1340930862-1405011213-2821322012-1000\desktop.ini.tmp
    Filesize

    85KB

    MD5

    4be875d8e7f2b6b5080517a639381c68

    SHA1

    48abd98ad6a92e8802f3642720739642e3f7ab43

    SHA256

    49fcb69bbe8e3286e6b94280e02a9ffc2630896fd13441e4299cbf32db250673

    SHA512

    1bacd3b7032b4dd9789d8f1aa9e7a6957e4f0dde1a5752dc4342d0bb2e093eb2d556841f9e822f080360b12f26697407e7f48b4b498148992f3f50961eed17a3

  • C:\MSOCache\All Users\{90140000-0011-0000-0000-0000000FF1CE}-C\Office64WW.xml.tmp
    Filesize

    94KB

    MD5

    5767243ac5993f44577a870973e5bea8

    SHA1

    01fc1f4be6bc5bca1aa7a192b611f00526816766

    SHA256

    6475139f3dc97673a8cea46a2c942caa7aa258e2b8080005ab5d4a6a1ddc2770

    SHA512

    107c79313b07ce856f9ebb737b7ef54973d48ef24217fb2f724732c66f0b2d73570a019112fe54060a7cd2ad855da0c2bf87cd3156e1cf93d854d43b1f9e917e