Analysis
-
max time kernel
140s -
max time network
149s -
platform
windows10-2004_x64 -
resource
win10v2004-20240508-en -
resource tags
arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system -
submitted
01-07-2024 04:10
Behavioral task
behavioral1
Sample
3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe
Resource
win7-20240508-en
General
-
Target
3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe
-
Size
1.6MB
-
MD5
49ed775e66e2cd74be732cc95bab5ef0
-
SHA1
9b10b9e0ec21e85e2c0ec8a07c774488abb58cdb
-
SHA256
3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881
-
SHA512
c290e2bdd9e920378a4698b276e3d43269066ce3d157cb5d16562714715abd5e9903218d0160da18ee145621eb597220d7acc4baf1b028f7ddaa6dbb26462563
-
SSDEEP
24576:kEoD7eAzxG0Jc0a1VjXsIQRJ5OTJ7hIVymFNlMtRVblP9PIjo3rSAp0sUPYud9m4:kZzju1VbsIQe/I07SAp0sUPYu7Uo7
Malware Config
Signatures
-
Detect Blackmoon payload 10 IoCs
Processes:
resource yara_rule behavioral2/memory/2148-10-0x0000000000AE0000-0x0000000000C9B000-memory.dmp family_blackmoon behavioral2/memory/2148-15-0x0000000000AE0000-0x0000000000C9B000-memory.dmp family_blackmoon behavioral2/memory/2148-16-0x0000000000AE0000-0x0000000000C9B000-memory.dmp family_blackmoon behavioral2/memory/2148-19-0x0000000000AE0000-0x0000000000C9B000-memory.dmp family_blackmoon behavioral2/memory/2148-18-0x0000000000AE0000-0x0000000000C9B000-memory.dmp family_blackmoon behavioral2/memory/2148-14-0x0000000000AE0000-0x0000000000C9B000-memory.dmp family_blackmoon behavioral2/memory/2148-13-0x0000000000AE0000-0x0000000000C9B000-memory.dmp family_blackmoon behavioral2/memory/2148-11-0x0000000000AE0000-0x0000000000C9B000-memory.dmp family_blackmoon behavioral2/memory/2148-20-0x0000000000AE0000-0x0000000000C9B000-memory.dmp family_blackmoon behavioral2/memory/2148-25-0x0000000000AE0000-0x0000000000C9B000-memory.dmp family_blackmoon -
Drops startup file 1 IoCs
Processes:
3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exedescription ioc process File created C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WPS.lnk 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe -
Processes:
resource yara_rule behavioral2/memory/2148-9-0x0000000002870000-0x0000000002888000-memory.dmp upx -
Enumerates physical storage devices 1 TTPs
Attempts to interact with connected storage/optical drive(s).
-
Suspicious behavior: EnumeratesProcesses 64 IoCs
Processes:
3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exepid process 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe -
Suspicious use of AdjustPrivilegeToken 8 IoCs
Processes:
3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exedescription pid process Token: SeDebugPrivilege 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe Token: SeLockMemoryPrivilege 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe Token: SeCreateGlobalPrivilege 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe Token: SeBackupPrivilege 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe Token: SeRestorePrivilege 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe Token: SeShutdownPrivilege 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe Token: SeCreateTokenPrivilege 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe Token: SeTakeOwnershipPrivilege 2148 3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe
Processes
-
C:\Users\Admin\AppData\Local\Temp\3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\3464397fe5b97bef1dedab8818a3f0679d555b3f0264ce6c539f45941f0b5881_NeikiAnalytics.exe"1⤵
- Drops startup file
- Suspicious behavior: EnumeratesProcesses
- Suspicious use of AdjustPrivilegeToken
Network
MITRE ATT&CK Matrix ATT&CK v13
Replay Monitor
Loading Replay Monitor...
Downloads
-
memory/2148-10-0x0000000000AE0000-0x0000000000C9B000-memory.dmpFilesize
1.7MB
-
memory/2148-15-0x0000000000AE0000-0x0000000000C9B000-memory.dmpFilesize
1.7MB
-
memory/2148-16-0x0000000000AE0000-0x0000000000C9B000-memory.dmpFilesize
1.7MB
-
memory/2148-19-0x0000000000AE0000-0x0000000000C9B000-memory.dmpFilesize
1.7MB
-
memory/2148-18-0x0000000000AE0000-0x0000000000C9B000-memory.dmpFilesize
1.7MB
-
memory/2148-14-0x0000000000AE0000-0x0000000000C9B000-memory.dmpFilesize
1.7MB
-
memory/2148-13-0x0000000000AE0000-0x0000000000C9B000-memory.dmpFilesize
1.7MB
-
memory/2148-12-0x0000000002B30000-0x0000000002B89000-memory.dmpFilesize
356KB
-
memory/2148-11-0x0000000000AE0000-0x0000000000C9B000-memory.dmpFilesize
1.7MB
-
memory/2148-9-0x0000000002870000-0x0000000002888000-memory.dmpFilesize
96KB
-
memory/2148-6-0x0000000000DD0000-0x0000000000DFB000-memory.dmpFilesize
172KB
-
memory/2148-8-0x0000000000B3B000-0x0000000000B3C000-memory.dmpFilesize
4KB
-
memory/2148-0-0x0000000010000000-0x0000000010109000-memory.dmpFilesize
1.0MB
-
memory/2148-20-0x0000000000AE0000-0x0000000000C9B000-memory.dmpFilesize
1.7MB
-
memory/2148-23-0x0000000002B30000-0x0000000002B89000-memory.dmpFilesize
356KB
-
memory/2148-24-0x0000000002B30000-0x0000000002B89000-memory.dmpFilesize
356KB
-
memory/2148-25-0x0000000000AE0000-0x0000000000C9B000-memory.dmpFilesize
1.7MB
-
memory/2148-27-0x0000000002B30000-0x0000000002B89000-memory.dmpFilesize
356KB
-
memory/2148-28-0x0000000002B30000-0x0000000002B89000-memory.dmpFilesize
356KB
-
memory/2148-32-0x0000000002B30000-0x0000000002B89000-memory.dmpFilesize
356KB
-
memory/2148-33-0x0000000002B30000-0x0000000002B89000-memory.dmpFilesize
356KB
-
memory/2148-36-0x0000000002B30000-0x0000000002B89000-memory.dmpFilesize
356KB
-
memory/2148-37-0x0000000002B30000-0x0000000002B89000-memory.dmpFilesize
356KB
-
memory/2148-40-0x0000000002B30000-0x0000000002B89000-memory.dmpFilesize
356KB
-
memory/2148-41-0x0000000002B30000-0x0000000002B89000-memory.dmpFilesize
356KB
-
memory/2148-45-0x0000000002B30000-0x0000000002B89000-memory.dmpFilesize
356KB
-
memory/2148-46-0x0000000002B30000-0x0000000002B89000-memory.dmpFilesize
356KB