Analysis
-
max time kernel
119s -
max time network
120s -
platform
windows7_x64 -
resource
win7-20240508-en -
resource tags
arch:x64arch:x86image:win7-20240508-enlocale:en-usos:windows7-x64system -
submitted
01-07-2024 07:41
Behavioral task
behavioral1
Sample
405a929ccb50ec5d72bbb978f24b0a3a7290f408a2742bd55f31f716f967984c_NeikiAnalytics.pdf
Resource
win7-20240508-en
Behavioral task
behavioral2
Sample
405a929ccb50ec5d72bbb978f24b0a3a7290f408a2742bd55f31f716f967984c_NeikiAnalytics.pdf
Resource
win10v2004-20240508-en
General
-
Target
405a929ccb50ec5d72bbb978f24b0a3a7290f408a2742bd55f31f716f967984c_NeikiAnalytics.pdf
-
Size
39KB
-
MD5
9ada77bd2a55a9088a2bffd2289b6080
-
SHA1
96174fbc2ad790defaeb57bd3b43ac9a1c698633
-
SHA256
405a929ccb50ec5d72bbb978f24b0a3a7290f408a2742bd55f31f716f967984c
-
SHA512
a044f37840381a534857a2353fe744afad559b5a4163ef7679f224411399e024f902c3084f95cbdf21b1a2bc12403f1cc8e23c690be557dd262c4209ddafa11a
-
SSDEEP
768:DgGzpDI90PIHZOr588d7sD+ABacgVoSi7UnpD3MVMT2rW+n:8GF89Z8ds5VvApD8VnrWK
Malware Config
Signatures
-
Suspicious behavior: GetForegroundWindowSpam 1 IoCs
Processes:
AcroRd32.exepid process 1728 AcroRd32.exe -
Suspicious use of SetWindowsHookEx 3 IoCs
Processes:
AcroRd32.exepid process 1728 AcroRd32.exe 1728 AcroRd32.exe 1728 AcroRd32.exe
Processes
-
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe"C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe" "C:\Users\Admin\AppData\Local\Temp\405a929ccb50ec5d72bbb978f24b0a3a7290f408a2742bd55f31f716f967984c_NeikiAnalytics.pdf"1⤵
- Suspicious behavior: GetForegroundWindowSpam
- Suspicious use of SetWindowsHookEx
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Users\Admin\AppData\Roaming\Adobe\Acrobat\9.0\SharedDataEventsFilesize
3KB
MD5d213193d1cd9c925f11971b7b0da42b9
SHA1dc5a37277ab714858e3f294d9a20eedfc8bac76d
SHA2563a292b013d0d54e51802f5b6955f3db1b0fbbf01a3286622f94547a98a3a8479
SHA5127ca28c6949359258358b36a8364f41c075e54ab92878f46032c8ed6795c54c94c4aabbe8ba64aeabe9b021f90494c8a7019e702f11c45af225c3670b04a640e3