Analysis

  • max time kernel
    150s
  • max time network
    49s
  • platform
    windows10-2004_x64
  • resource
    win10v2004-20240508-en
  • resource tags

    arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system
  • submitted
    01-07-2024 05:42

General

  • Target

    398486cff13d9fe5943c1e122391a3c181a386a3ce9a5099bd3a9ad34f6a3117_NeikiAnalytics.exe

  • Size

    51KB

  • MD5

    f7011272e14703dd14e9f4b1895d4ed0

  • SHA1

    0e030ccdf30d3d25d37d20636bed9f6d7552cc5d

  • SHA256

    398486cff13d9fe5943c1e122391a3c181a386a3ce9a5099bd3a9ad34f6a3117

  • SHA512

    597c8ddcaf294a93426cbecf5195bc713c57b6875e830ab6f2505ef4061a762ac71460edb35d52750eb8932e04823cf47aaa8f42d885035f3809bc5f291d81e1

  • SSDEEP

    384:GBt7Br5xjLMuLAgA71FbhvDl3DG71ul3DG71XUmUIYFAHsi3:W7BlpNLpARFbhblkYlkuvIYFdi

Score
9/10

Malware Config

Signatures

  • Renames multiple (5275) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\398486cff13d9fe5943c1e122391a3c181a386a3ce9a5099bd3a9ad34f6a3117_NeikiAnalytics.exe
    "C:\Users\Admin\AppData\Local\Temp\398486cff13d9fe5943c1e122391a3c181a386a3ce9a5099bd3a9ad34f6a3117_NeikiAnalytics.exe"
    1⤵
    • Drops file in Program Files directory
    PID:2508

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-1337824034-2731376981-3755436523-1000\desktop.ini.tmp
    Filesize

    51KB

    MD5

    60592f9b0c37b8f938316465d64d7cfe

    SHA1

    8b4a9d1bb7500b67cf8abf0d03cd1f29120f7654

    SHA256

    72905dbf0697e4bf817aa9d0948fc5ab60efa6bb406e9928e59c39908df5c866

    SHA512

    c63d675120d722145d1f385f26298fcd3403ebb8c2ce53b4c27a8b5e24db9979be264e2750db2f6ba6d08a58c2ddbd1873dd9ed439a8146ef88aa71f721d4c31

  • C:\Program Files\7-Zip\7-zip.dll.tmp
    Filesize

    150KB

    MD5

    3fff72a45c62435245c7da0091d1420d

    SHA1

    6a8d6cceb8910c117e63b7247d32b6bfc6409eac

    SHA256

    43876e170a0e05b1810fdc713a4eed372ce6e3e95c6669c2db37bdb465726961

    SHA512

    ad89714ac0428a497c634011d9cebccdb74196ab38cd0969a7c1f4aff973293b274e4158bb7665fd08bac257846c1ee459011febc46b4c98c86aebf44e8fea0a