Analysis

  • max time kernel
    149s
  • max time network
    102s
  • platform
    windows10-2004_x64
  • resource
    win10v2004-20240611-en
  • resource tags

    arch:x64arch:x86image:win10v2004-20240611-enlocale:en-usos:windows10-2004-x64system
  • submitted
    01-07-2024 05:28

General

  • Target

    38d71330ccd1c2305dd8e89cb16d451fb77ed19fd884d416e4bcbe7adad9f1b9_NeikiAnalytics.exe

  • Size

    37KB

  • MD5

    5e4cfc7659d0bd94d5751e0ad85db950

  • SHA1

    9105e7e73aa2b98dd785855fba142468ff016152

  • SHA256

    38d71330ccd1c2305dd8e89cb16d451fb77ed19fd884d416e4bcbe7adad9f1b9

  • SHA512

    d21dffaa6d1c2e24245a4d577d5fe623f5c4f8a6357afa0bed38a47823e727ed761e3defb5ece1399ad65c6c519dd3caf733efe3329b924213ee4b579a95fba5

  • SSDEEP

    384:GBt7Br5xjL9AgA71FbhvuNBN2TQ1nrq9q4+:W7BlpppARFbhknrl

Score
9/10

Malware Config

Signatures

  • Renames multiple (5190) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\38d71330ccd1c2305dd8e89cb16d451fb77ed19fd884d416e4bcbe7adad9f1b9_NeikiAnalytics.exe
    "C:\Users\Admin\AppData\Local\Temp\38d71330ccd1c2305dd8e89cb16d451fb77ed19fd884d416e4bcbe7adad9f1b9_NeikiAnalytics.exe"
    1⤵
    • Drops file in Program Files directory
    PID:2280

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-200405930-3877336739-3533750831-1000\desktop.ini.tmp
    Filesize

    37KB

    MD5

    b4bfff7622d8aa9e23e3009b37583807

    SHA1

    3290bc7375a6c72051b11b619218cd129490964d

    SHA256

    736c38eb39982c5f3772f9fed2ac7214f07dd74b6fa2769631f22b4d5a8ac4ff

    SHA512

    b6e96a8248cc1d1be8506c3820a944e76710b560f0ecd943ea6b295fd43fa65733d0b6a1471fd0b0f4398071d59b658d640b43d9b5d2044e8bfef68f41955460

  • C:\Program Files\7-Zip\7-zip.dll.tmp
    Filesize

    136KB

    MD5

    a59fba2efdbd41193ebe07b7a94cd718

    SHA1

    c07309ff00cef95c4938813fee8f9793fa715926

    SHA256

    bed0394eca91dd2945fed3157d66116a0e0078ebfcd2b6840aa2408de77834f1

    SHA512

    e85c4e34c3cae327de7de054d6f52627ebacf58d3a66ef46ad28639c1519e0c4cc6b989a525bb77864c7edaddf68e6adea7e8b3e99506833bfd53e48b8144362