Analysis

  • max time kernel
    149s
  • max time network
    119s
  • platform
    windows7_x64
  • resource
    win7-20231129-en
  • resource tags

    arch:x64arch:x86image:win7-20231129-enlocale:en-usos:windows7-x64system
  • submitted
    01-07-2024 05:42

General

  • Target

    398486cff13d9fe5943c1e122391a3c181a386a3ce9a5099bd3a9ad34f6a3117_NeikiAnalytics.exe

  • Size

    51KB

  • MD5

    f7011272e14703dd14e9f4b1895d4ed0

  • SHA1

    0e030ccdf30d3d25d37d20636bed9f6d7552cc5d

  • SHA256

    398486cff13d9fe5943c1e122391a3c181a386a3ce9a5099bd3a9ad34f6a3117

  • SHA512

    597c8ddcaf294a93426cbecf5195bc713c57b6875e830ab6f2505ef4061a762ac71460edb35d52750eb8932e04823cf47aaa8f42d885035f3809bc5f291d81e1

  • SSDEEP

    384:GBt7Br5xjLMuLAgA71FbhvDl3DG71ul3DG71XUmUIYFAHsi3:W7BlpNLpARFbhblkYlkuvIYFdi

Score
9/10

Malware Config

Signatures

  • Renames multiple (3673) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\398486cff13d9fe5943c1e122391a3c181a386a3ce9a5099bd3a9ad34f6a3117_NeikiAnalytics.exe
    "C:\Users\Admin\AppData\Local\Temp\398486cff13d9fe5943c1e122391a3c181a386a3ce9a5099bd3a9ad34f6a3117_NeikiAnalytics.exe"
    1⤵
    • Drops file in Program Files directory
    PID:1420

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-3627615824-4061627003-3019543961-1000\desktop.ini.tmp
    Filesize

    51KB

    MD5

    cbd616e673d97cede3f8fdced2a32607

    SHA1

    54945dcc9be931453ed105f4393bc9f38b2ffd0f

    SHA256

    ea2abad367df3cdcb84348638f028fc46fada20f178ae0afa56428db92695ce3

    SHA512

    66cdbbd7680b7f46bb507414a2d2ffa3f17166ad707c819da5cabcfe2ec14f3bc8e5479d458912a83c5af11af50a2922bcf84e957b317dafa69a3f64edb0ffe8

  • C:\MSOCache\All Users\{90140000-0011-0000-0000-0000000FF1CE}-C\Office64WW.xml.tmp
    Filesize

    60KB

    MD5

    7d0f464c95e638c1d71fc625ccac8dd2

    SHA1

    9a6d4f0d33b129b2512d1c24ecd2a0e11b0d8fe4

    SHA256

    a06dc355efd2d744e2f2aff0a1649caf05d98a4b7b889297c392c308080c8450

    SHA512

    96f66903d0a74b24107a5bb68ca5945f8336e1516825e364bc462ece53aa30184a22c7c0bd31eee30af7ea0268973de8358d3751c8e9ebdc0019edacfe55ad15