Analysis
-
max time kernel
150s -
max time network
145s -
platform
windows10-2004_x64 -
resource
win10v2004-20240508-en -
resource tags
arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system -
submitted
01-07-2024 05:14
Static task
static1
Behavioral task
behavioral1
Sample
3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe
Resource
win7-20240221-en
Behavioral task
behavioral2
Sample
3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe
Resource
win10v2004-20240508-en
General
-
Target
3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe
-
Size
81KB
-
MD5
ffa5980777799e90ae2b7c9ed04f3390
-
SHA1
11b1e91bad00177f822fe4c286b7006814d1cda4
-
SHA256
3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a
-
SHA512
1e98fd9f8fa46e7c32aa93be2ee236e7af55cdc4b6a6f840e36abbdfad8121847468354cf89d2e09b54711389b5e22714ff2e688e31ea7baa1a97e797db83097
-
SSDEEP
768:W7BlpDpARFbhYQkQjjIXYvPXzWPXzK3733uF4V7en5c5HChCrmh1444REXBwzEXS:W7ZDpApYbWjIoPyPoLzV7c6Sh1Xw
Malware Config
Signatures
-
Renames multiple (5020) files with added filename extension
This suggests ransomware activity of encrypting all the files on the system.
-
Drops file in Program Files directory 64 IoCs
Processes:
3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exedescription ioc process File created C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RINTL.et-ee.dll.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Common Files\System\Ole DB\sqloledb.rll.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.NETCore.App\7.0.16\System.Collections.Specialized.dll.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Google\Chrome\Application\110.0.5481.104\libGLESv2.dll.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Licenses16\PowerPointVL_MAK-ul-oob.xrm-ms.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\Microsoft.Data.ConnectionUI.Dialog.dll.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Office16\sdxs\FA000000018\cardview\lib\native-common\assets\cardview-moreimages.png.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\7.0.16\de\UIAutomationTypes.resources.dll.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Java\jdk-1.8\jre\legal\javafx\mesa3d.md.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Java\jre-1.8\bin\api-ms-win-core-file-l1-2-0.dll.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Licenses16\ProPlus2019R_OEM_Perp2-ul-phn.xrm-ms.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Office16\1033\PSRCHKEY.DAT.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\Microsoft.Mashup.Container.Loader.exe.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Common Files\System\ado\msado28.tlb.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\6.0.27\tr\WindowsBase.resources.dll.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Java\jre-1.8\legal\jdk\giflib.md.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\7-Zip\Lang\it.txt.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.NETCore.App\7.0.16\System.IO.UnmanagedMemoryStream.dll.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Licenses16\ProPlus2019XC2RVL_MAKC2R-ul-phn.xrm-ms.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Office16\SAMPLES\SOLVSAMP.XLS.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Office16\SDXHelper.exe.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ink\bg-BG\tipresx.dll.mui.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\osknav.xml.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Java\jre-1.8\bin\javacpl.cpl.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Java\jre-1.8\bin\resource.dll.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Office16\ADDINS\EduWorks Data Streamer Add-In\MsoAriaCApiWrapper.dll.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Common Files\System\ado\msado26.tlb.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.27\System.Runtime.Extensions.dll.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\6.0.27\cs\System.Windows.Forms.Design.resources.dll.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\6.0.27\pt-BR\Microsoft.VisualBasic.Forms.resources.dll.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Licenses16\OneNoteR_OEM_Perp-ul-oob.xrm-ms.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Common Files\System\Ole DB\it-IT\sqlxmlx.rll.mui.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.2\System.Reflection.TypeExtensions.dll.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Google\Chrome\Application\chrome.exe.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Java\jdk-1.8\legal\jdk\giflib.md.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Office16\1033\GRAPH.HXS.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Office16\LivePersonaCard\images\default\linkedin_ghost_profile_large.png.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base.xml.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.27\System.Collections.Specialized.dll.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Internet Explorer\iexplore.exe.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Java\jre-1.8\lib\cmm\GRAY.pf.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Licenses16\MondoR_EnterpriseSub_Bypass30-ppd.xrm-ms.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Licenses16\ProjectStdVL_KMS_Client-ppd.xrm-ms.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Office16\Bibliography\Style\MLASeventhEditionOfficeOnline.xsl.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ink\en-US\tabskb.dll.mui.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Common Files\microsoft shared\ink\ro-RO\tipresx.dll.mui.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\8.0.2\tr\UIAutomationClient.resources.dll.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Office16\MSIPC\en-us\msipc.dll.mui.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\BlockUnprotect.dotx.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\6.0.27\ja\ReachFramework.resources.dll.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\7.0.16\ko\System.Windows.Input.Manipulations.resources.dll.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Java\jdk-1.8\jre\bin\policytool.exe.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Licenses16\ProjectStdO365R_SubTest-ppd.xrm-ms.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\7.0.16\zh-Hant\System.Windows.Input.Manipulations.resources.dll.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\8.0.2\tr\System.Windows.Forms.Design.resources.dll.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Office16\PROOF\msth8ES.DLL.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\7-Zip\Lang\nn.txt.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\6.0.27\PresentationFramework.Luna.dll.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Licenses16\VisioPro2019R_Grace-ul-oob.xrm-ms.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Office15\pkeyconfig-office.xrm-ms.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Office16\MSIPC\pt\msipc.dll.mui.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Office16\PAGESIZE\PGMN048.XML.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_SubTrial4-pl.xrm-ms.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe File created C:\Program Files\Microsoft Office\root\Licenses16\Outlook2019VL_MAK_AE-ul-oob.xrm-ms.tmp 3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe
Processes
-
C:\Users\Admin\AppData\Local\Temp\3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe"1⤵
- Drops file in Program Files directory
-
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --no-appcompat-clear --field-trial-handle=4256,i,18168883380598738769,14202261231630113808,262144 --variations-seed-version --mojo-platform-channel-handle=4064 /prefetch:81⤵
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\$Recycle.Bin\S-1-5-21-1181767204-2009306918-3718769404-1000\desktop.ini.tmpFilesize
81KB
MD533edc4c515020f8e5f46a2824ead0d18
SHA114e23ad41a596095e8f57bd143ee0ca058340fb0
SHA256c49474a5523895b7b33aca1fdb16a806e71206c8ebf509839ac5aa6a86f2c15a
SHA512b5ea4cf4b1ac1a091476063cd498ff40087940fd968f259e64e5f664965adbeca605bdb6b8cb6c489a99a493546be2025800f2645470601b798c54b963dc394a
-
C:\Program Files\7-Zip\7-zip.chm.exeFilesize
194KB
MD537ed56607802bfbdb247ced2d3a4f2e5
SHA1f937ac189055690a416b2695da9cbb70da36a7af
SHA2564a62e844a83a2844dcb38fc089c3b3751decf3c654080d52b5c4e3f87bef788d
SHA5121378e38e29aa485bfb8e6abdc8ba194e0b0d3b47e34d1a251de03d2cfcc707178500077566e130d8e01043e1886a50974ed77851f669408c3a14f7e735276786