Analysis

  • max time kernel
    150s
  • max time network
    127s
  • platform
    windows7_x64
  • resource
    win7-20240221-en
  • resource tags

    arch:x64arch:x86image:win7-20240221-enlocale:en-usos:windows7-x64system
  • submitted
    01-07-2024 04:15

General

  • Target

    349dfd45eb436cedb61a0c7a42d2292a29441b31e6dd54bee1f1879183ee406e_NeikiAnalytics.exe

  • Size

    98KB

  • MD5

    aa3adbc68bb23df78a3f1eb25e75a470

  • SHA1

    0adf5cc8e9d203f835ed2b318e998832b9e280cb

  • SHA256

    349dfd45eb436cedb61a0c7a42d2292a29441b31e6dd54bee1f1879183ee406e

  • SHA512

    73b0da6bf334be5802baf00ab6a4be6f2e3dd713f3022659154787a8f9051be4d302322b8dfe8ce6e681bfea9624e7455ab0e697e33972898dd33b2af954d43a

  • SSDEEP

    3072:6e7WpMaxeb0CYJ97lEYNR73e+eKZOf7fOw2wSBr:RqKvb0CYJ973e+eKZOf7fa

Score
9/10

Malware Config

Signatures

  • Renames multiple (2655) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\349dfd45eb436cedb61a0c7a42d2292a29441b31e6dd54bee1f1879183ee406e_NeikiAnalytics.exe
    "C:\Users\Admin\AppData\Local\Temp\349dfd45eb436cedb61a0c7a42d2292a29441b31e6dd54bee1f1879183ee406e_NeikiAnalytics.exe"
    1⤵
    • Drops file in Program Files directory
    PID:2860

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-1298544033-3225604241-2703760938-1000\desktop.ini.tmp
    Filesize

    98KB

    MD5

    6d244df42a2121008f5f9d9d4b17d69c

    SHA1

    533bc97ba47b674509586f77fc491eb79013b257

    SHA256

    5999d3e44419c0deee44a6afd94063117c487ca4c81b6731801187d0b6bb520a

    SHA512

    d0aa4e22255f276249ce0f9d7635298e8baadb3f919df762cea6fd949f2bfb1a500e0e222b26f39a2d67c11179a3780be8577cb090206313196f88abca5e3805

  • C:\MSOCache\All Users\{90140000-0011-0000-0000-0000000FF1CE}-C\Office64WW.xml.tmp
    Filesize

    107KB

    MD5

    4e092eb40d1d20030e0923362c3ee2e2

    SHA1

    35a9b4930de3ea0e65a38af964a5ee81761ceac4

    SHA256

    a908217d2654f5bd60cb464f15dab44970c73b6d6ce370d6d092885ad2f30a2c

    SHA512

    dfde1d252dce2252955a80282c92b7ecc5094118f207a0b8ae55388737efc36ad69b74c8aab7522e6e1e065d615e8bf655567a7b644f620b52742b5629aa1460