Analysis

  • max time kernel
    150s
  • max time network
    145s
  • platform
    windows10-2004_x64
  • resource
    win10v2004-20240508-en
  • resource tags

    arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system
  • submitted
    01-07-2024 05:14

General

  • Target

    3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe

  • Size

    81KB

  • MD5

    ffa5980777799e90ae2b7c9ed04f3390

  • SHA1

    11b1e91bad00177f822fe4c286b7006814d1cda4

  • SHA256

    3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a

  • SHA512

    1e98fd9f8fa46e7c32aa93be2ee236e7af55cdc4b6a6f840e36abbdfad8121847468354cf89d2e09b54711389b5e22714ff2e688e31ea7baa1a97e797db83097

  • SSDEEP

    768:W7BlpDpARFbhYQkQjjIXYvPXzWPXzK3733uF4V7en5c5HChCrmh1444REXBwzEXS:W7ZDpApYbWjIoPyPoLzV7c6Sh1Xw

Score
9/10

Malware Config

Signatures

  • Renames multiple (5020) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe
    "C:\Users\Admin\AppData\Local\Temp\3807c9324849e420d21dea1e750cbd85751b6f2980663467ac81907bbc6afb6a_NeikiAnalytics.exe"
    1⤵
    • Drops file in Program Files directory
    PID:1268
  • C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
    "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --no-appcompat-clear --field-trial-handle=4256,i,18168883380598738769,14202261231630113808,262144 --variations-seed-version --mojo-platform-channel-handle=4064 /prefetch:8
    1⤵
      PID:4820

    Network

    MITRE ATT&CK Matrix

    Replay Monitor

    Loading Replay Monitor...

    Downloads

    • C:\$Recycle.Bin\S-1-5-21-1181767204-2009306918-3718769404-1000\desktop.ini.tmp
      Filesize

      81KB

      MD5

      33edc4c515020f8e5f46a2824ead0d18

      SHA1

      14e23ad41a596095e8f57bd143ee0ca058340fb0

      SHA256

      c49474a5523895b7b33aca1fdb16a806e71206c8ebf509839ac5aa6a86f2c15a

      SHA512

      b5ea4cf4b1ac1a091476063cd498ff40087940fd968f259e64e5f664965adbeca605bdb6b8cb6c489a99a493546be2025800f2645470601b798c54b963dc394a

    • C:\Program Files\7-Zip\7-zip.chm.exe
      Filesize

      194KB

      MD5

      37ed56607802bfbdb247ced2d3a4f2e5

      SHA1

      f937ac189055690a416b2695da9cbb70da36a7af

      SHA256

      4a62e844a83a2844dcb38fc089c3b3751decf3c654080d52b5c4e3f87bef788d

      SHA512

      1378e38e29aa485bfb8e6abdc8ba194e0b0d3b47e34d1a251de03d2cfcc707178500077566e130d8e01043e1886a50974ed77851f669408c3a14f7e735276786