General

  • Target

    38ed4afeb601760455ed46dfaec92d71cc48e34a8a77731c00766bdea113a612_NeikiAnalytics.exe

  • Size

    169KB

  • Sample

    240701-f7r49axdra

  • MD5

    f25f0b4cd195f5b906b9350315aabc90

  • SHA1

    1dced985226721fec38c1f0df03afaa2a2b1125a

  • SHA256

    38ed4afeb601760455ed46dfaec92d71cc48e34a8a77731c00766bdea113a612

  • SHA512

    e184246a92bcf29b00e1ebbc48be0e79de4e0cdd9960f190f8b135b836d50985958f57b5f0d8b0a8c4d05265ba912fea19ce7c955d0720f2daecca35084ef739

  • SSDEEP

    3072:6pWpUFpEhLfyBtPf50FWkFpPDze/qFsxEhLfyBtPf50FWkFpPDze/qFslEhLfyBS:PqFF2Ie+eFC27qFF2Ie+eFC2h

Score
9/10

Malware Config

Targets

    • Target

      38ed4afeb601760455ed46dfaec92d71cc48e34a8a77731c00766bdea113a612_NeikiAnalytics.exe

    • Size

      169KB

    • MD5

      f25f0b4cd195f5b906b9350315aabc90

    • SHA1

      1dced985226721fec38c1f0df03afaa2a2b1125a

    • SHA256

      38ed4afeb601760455ed46dfaec92d71cc48e34a8a77731c00766bdea113a612

    • SHA512

      e184246a92bcf29b00e1ebbc48be0e79de4e0cdd9960f190f8b135b836d50985958f57b5f0d8b0a8c4d05265ba912fea19ce7c955d0720f2daecca35084ef739

    • SSDEEP

      3072:6pWpUFpEhLfyBtPf50FWkFpPDze/qFsxEhLfyBtPf50FWkFpPDze/qFslEhLfyBS:PqFF2Ie+eFC27qFF2Ie+eFC2h

    Score
    9/10
    • Renames multiple (4515) files with added filename extension

      This suggests ransomware activity of encrypting all the files on the system.

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix

Tasks