Analysis

  • max time kernel
    150s
  • max time network
    122s
  • platform
    windows7_x64
  • resource
    win7-20240611-en
  • resource tags

    arch:x64arch:x86image:win7-20240611-enlocale:en-usos:windows7-x64system
  • submitted
    01-07-2024 05:57

General

  • Target

    3a6849ec4bdd973fcda6379161889150923c4b085e8793bd69453348402dfee6_NeikiAnalytics.exe

  • Size

    48KB

  • MD5

    d3974c4758e4694f7d2c7b9ff1cf9fa0

  • SHA1

    1fdcbc18315fb901125d0c2f38757ec961416c76

  • SHA256

    3a6849ec4bdd973fcda6379161889150923c4b085e8793bd69453348402dfee6

  • SHA512

    7c6ec437e6fd4b3246786da6a5346deb9c24b6ac1f2829c16f54df04a4b14d74bbb0ea78ffa3885ca5d0fc7725a7039089406df0c372449860c171ae7b284194

  • SSDEEP

    768:W7BlpNLpARFbhblkYlkuvIYFdqRHRcbNb3:W7ZNLpApCZuvIYXqRHRmJ3

Score
9/10

Malware Config

Signatures

  • Renames multiple (3555) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\3a6849ec4bdd973fcda6379161889150923c4b085e8793bd69453348402dfee6_NeikiAnalytics.exe
    "C:\Users\Admin\AppData\Local\Temp\3a6849ec4bdd973fcda6379161889150923c4b085e8793bd69453348402dfee6_NeikiAnalytics.exe"
    1⤵
    • Drops file in Program Files directory
    PID:2132

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-2812790648-3157963462-487717889-1000\desktop.ini.tmp
    Filesize

    48KB

    MD5

    9f6e7fd523fe702705a6bc054d27c479

    SHA1

    4736a2f98c94bedf36e70f82c6c04635657045d7

    SHA256

    0e31552afe333f71702364ab95b4de4d481a6bd25340f0611200971d7db54e2d

    SHA512

    95cca4ce3f7fb7454b3d6a57b2ec86055743ed77697caae0816249ba21a2612ff56023aab7db601540576359c85188a14a0b0990e29f25174da552aa95b9a544

  • C:\MSOCache\All Users\{90140000-0011-0000-0000-0000000FF1CE}-C\Office64WW.xml.tmp
    Filesize

    57KB

    MD5

    52e1cb9eb7dadcc76f5e3669431117e1

    SHA1

    7008313a0da6a833756b5fd7e49470359a60cd1c

    SHA256

    a9e7628df868ccb1f5756dd997eecf14e426fe9dacdb9910ed24a9d1a5913f9a

    SHA512

    3c25112e14fbc4012550ece95fbe45a3b969a49e3810d05a3721313ce5c0a75652fa514158729da2ee890b8a310c3cd98421951afe84aba13848d8a34aca4aa8