Analysis
-
max time kernel
9s -
max time network
95s -
platform
windows10-2004_x64 -
resource
win10v2004-20240508-en -
resource tags
arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system -
submitted
01-07-2024 04:00
Static task
static1
Behavioral task
behavioral1
Sample
33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe
Resource
win7-20240611-en
Behavioral task
behavioral2
Sample
33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe
Resource
win10v2004-20240508-en
General
-
Target
33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe
-
Size
85KB
-
MD5
57a51ac463ae8b49c3ce8fbaafa5d800
-
SHA1
063a6ae99fa8725c9bfe41c195edfb33d688edcc
-
SHA256
33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e
-
SHA512
56834445e42b80a6cb83603b70f792b5e8af7e14f13812732bc20d8a3975823035a9f62d0cee129d3dd4894905ed673dadf66ff52c0c9b488eceb30b3a19942f
-
SSDEEP
1536:W7ZhA7pApH1d9oVLQthbqbY9oVLQthbq51Rn6wt7t5m0m69YUpCUppXxXTXxXX:6e7WpP9oVLQthbYY9oVLQthbUrt7t5ma
Malware Config
Signatures
-
Renames multiple (219) files with added filename extension
This suggests ransomware activity of encrypting all the files on the system.
-
Drops file in Program Files directory 64 IoCs
Processes:
33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exedescription ioc process File created C:\Program Files\7-Zip\Lang\en.ttt.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ink\de-DE\rtscom.dll.mui.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ink\de-DE\ShapeCollector.exe.mui.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\7-Zip\Lang\fy.txt.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\7-Zip\Lang\ku.txt.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-file-l2-1-0.dll.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIsvSubsystemController.dll.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RINTL.he-il.dll.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RINTL.pt-br.dll.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RINTL.zh-cn.dll.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\7-Zip\7zG.exe.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\7-Zip\Lang\ja.txt.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\7-Zip\Lang\mng2.txt.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\7-Zip\Lang\si.txt.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ClickToRun\msvcr120.dll.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ink\ar-SA\tipresx.dll.mui.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\7-Zip\Lang\ps.txt.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-file-l1-2-0.dll.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RINTL.es-es.dll.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RINTL.id-id.dll.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ClickToRun\cpprestsdk.dll.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\7-Zip\Lang\he.txt.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ink\de-DE\InputPersonalization.exe.mui.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\7-Zip\Lang\nb.txt.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-private-l1-1-0.dll.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RHeartbeatConfig.xml.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RINTL.ro-ro.dll.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\7-Zip\Lang\it.txt.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\7-Zip\Lang\sl.txt.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-locale-l1-1-0.dll.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVClient.man.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVClientIsv.man.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems32.dll.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\7-Zip\Lang\bg.txt.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\7-Zip\Lang\ext.txt.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RINTL.bg-bg.dll.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\7-Zip\Lang\hi.txt.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\7-Zip\Lang\is.txt.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\7-Zip\Lang\kk.txt.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-stdio-l1-1-0.dll.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ClickToRun\C2R64.dll.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RINTL.sl-si.dll.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\7-Zip\Lang\da.txt.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\7-Zip\Lang\sa.txt.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-math-l1-1-0.dll.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RINTL.kk-kz.dll.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\7-Zip\Lang\co.txt.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\7-Zip\Lang\ga.txt.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\7-Zip\Lang\ms.txt.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIsvApi.dll.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ink\de-DE\InkObj.dll.mui.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVScripting.dll.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RINTL.ar-sa.dll.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RINTL.hr-hr.dll.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RINTL.sr-latn-rs.dll.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ClickToRun\ServiceWatcherSchedule.xml.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\7-Zip\Lang\an.txt.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\7-Zip\Lang\id.txt.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\7-Zip\Lang\mr.txt.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\7-Zip\Lang\th.txt.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-localization-l1-2-0.dll.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RINTL.hu-hu.dll.tmp 33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe
Processes
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\$Recycle.Bin\S-1-5-21-4124900551-4068476067-3491212533-1000\desktop.ini.tmpFilesize
85KB
MD51a3d02e9875d48283d9c87a0ace7176f
SHA1e0e3d346b6d87ebe8a3df6af210307d68ee9d2cb
SHA2566eb44d19830ae72349a2873e23e79c09c14328ed3499523ec127f287afbdea3c
SHA5129d82b2d03a385ef43a533c0ce6f62ec632c5e3a711efe8a11e4c4825f3e4e961aad072a2eabb0daa8346edc56d57b13b3c39ef9c93b9426d41e152f64a2738fd
-
C:\Program Files\7-Zip\7-zip.dll.tmpFilesize
184KB
MD5a0ac0c83638e25503ef446ca0205f558
SHA1fbe636f394c7ca152f30f963aef19fb4c6a064e5
SHA256c8c501ab9b61d0c34efc6ac6763bd101c9bae78d7d9d4cb05f1094c2b4882617
SHA51252c63e2ca15c15aae417f12b0046f53cd6165142fee1482ceb97ff2229e20e30da90f8472c25f4c4c5c634705a649f9cb97af4c89424a1a8e2ac9968e52f5bd4