Analysis
-
max time kernel
117s -
max time network
121s -
platform
windows7_x64 -
resource
win7-20240220-en -
resource tags
arch:x64arch:x86image:win7-20240220-enlocale:en-usos:windows7-x64system -
submitted
01-07-2024 07:23
Behavioral task
behavioral1
Sample
3f567e3e98fc0547a4c47401e10cff21ecf891b248a601b2713df061e27628ba_NeikiAnalytics.pdf
Resource
win7-20240220-en
Behavioral task
behavioral2
Sample
3f567e3e98fc0547a4c47401e10cff21ecf891b248a601b2713df061e27628ba_NeikiAnalytics.pdf
Resource
win10v2004-20240508-en
General
-
Target
3f567e3e98fc0547a4c47401e10cff21ecf891b248a601b2713df061e27628ba_NeikiAnalytics.pdf
-
Size
85KB
-
MD5
b1e062fd23c73e5c17661461ba7127e0
-
SHA1
5ab246ed10dfa3db8f701c8dd484bc77b058ef1c
-
SHA256
3f567e3e98fc0547a4c47401e10cff21ecf891b248a601b2713df061e27628ba
-
SHA512
1491df48c717f2b3df91e66683b51b3272f4487474162c9e4c614974b790f5e4fefcb4f036494090b3d43a62a4e38f803de23796f9341875e23f90b746bfdd05
-
SSDEEP
1536:kFGYnSKYJrTe5UDxTqhyAiCEaxylTsmY6MWaaI5/sFZGBagVhIHzI11pnI1+Z:kBnShTe5UDxGUAiCEaxqTs56TaaIgrQf
Malware Config
Signatures
-
Suspicious behavior: GetForegroundWindowSpam 1 IoCs
Processes:
AcroRd32.exepid process 2604 AcroRd32.exe -
Suspicious use of SetWindowsHookEx 3 IoCs
Processes:
AcroRd32.exepid process 2604 AcroRd32.exe 2604 AcroRd32.exe 2604 AcroRd32.exe
Processes
-
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe"C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe" "C:\Users\Admin\AppData\Local\Temp\3f567e3e98fc0547a4c47401e10cff21ecf891b248a601b2713df061e27628ba_NeikiAnalytics.pdf"1⤵
- Suspicious behavior: GetForegroundWindowSpam
- Suspicious use of SetWindowsHookEx
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Users\Admin\AppData\Roaming\Adobe\Acrobat\9.0\SharedDataEventsFilesize
3KB
MD53e7996b9599b6eef951f9f7ca70d4118
SHA13cb4a88b760a915c3a03729d9d50c7fe96ada340
SHA25668fb0a5d55dbd79aa2ce467c691a006e2b48c9660c7b43744637a903872d925d
SHA5122734b836aac5fd72fa7579051b329807ca651419e150bcd68e3b0d2d6991e599b9581013b7e282c67aafecec8b01dfd6dbbd189dc926c39d991def380d32f27f