Analysis

  • max time kernel
    9s
  • max time network
    95s
  • platform
    windows10-2004_x64
  • resource
    win10v2004-20240508-en
  • resource tags

    arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system
  • submitted
    01-07-2024 04:00

General

  • Target

    33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe

  • Size

    85KB

  • MD5

    57a51ac463ae8b49c3ce8fbaafa5d800

  • SHA1

    063a6ae99fa8725c9bfe41c195edfb33d688edcc

  • SHA256

    33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e

  • SHA512

    56834445e42b80a6cb83603b70f792b5e8af7e14f13812732bc20d8a3975823035a9f62d0cee129d3dd4894905ed673dadf66ff52c0c9b488eceb30b3a19942f

  • SSDEEP

    1536:W7ZhA7pApH1d9oVLQthbqbY9oVLQthbq51Rn6wt7t5m0m69YUpCUppXxXTXxXX:6e7WpP9oVLQthbYY9oVLQthbUrt7t5ma

Score
9/10

Malware Config

Signatures

  • Renames multiple (219) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe
    "C:\Users\Admin\AppData\Local\Temp\33c1144657cd99ecccc12efb7932be4ab5140273359b036944a24cadb533fd1e_NeikiAnalytics.exe"
    1⤵
    • Drops file in Program Files directory
    PID:1804

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-4124900551-4068476067-3491212533-1000\desktop.ini.tmp
    Filesize

    85KB

    MD5

    1a3d02e9875d48283d9c87a0ace7176f

    SHA1

    e0e3d346b6d87ebe8a3df6af210307d68ee9d2cb

    SHA256

    6eb44d19830ae72349a2873e23e79c09c14328ed3499523ec127f287afbdea3c

    SHA512

    9d82b2d03a385ef43a533c0ce6f62ec632c5e3a711efe8a11e4c4825f3e4e961aad072a2eabb0daa8346edc56d57b13b3c39ef9c93b9426d41e152f64a2738fd

  • C:\Program Files\7-Zip\7-zip.dll.tmp
    Filesize

    184KB

    MD5

    a0ac0c83638e25503ef446ca0205f558

    SHA1

    fbe636f394c7ca152f30f963aef19fb4c6a064e5

    SHA256

    c8c501ab9b61d0c34efc6ac6763bd101c9bae78d7d9d4cb05f1094c2b4882617

    SHA512

    52c63e2ca15c15aae417f12b0046f53cd6165142fee1482ceb97ff2229e20e30da90f8472c25f4c4c5c634705a649f9cb97af4c89424a1a8e2ac9968e52f5bd4