Analysis
-
max time kernel
120s -
max time network
120s -
platform
windows7_x64 -
resource
win7-20240611-en -
resource tags
arch:x64arch:x86image:win7-20240611-enlocale:en-usos:windows7-x64system -
submitted
01-07-2024 09:34
Behavioral task
behavioral1
Sample
47737c852a9b3e3ad1d9e6d96c3a6049dccb1c625b003e6423b163e6f850e99a_NeikiAnalytics.pdf
Resource
win7-20240611-en
Behavioral task
behavioral2
Sample
47737c852a9b3e3ad1d9e6d96c3a6049dccb1c625b003e6423b163e6f850e99a_NeikiAnalytics.pdf
Resource
win10v2004-20240508-en
General
-
Target
47737c852a9b3e3ad1d9e6d96c3a6049dccb1c625b003e6423b163e6f850e99a_NeikiAnalytics.pdf
-
Size
73KB
-
MD5
2a1f7756cdcc98eb6bfc20fb9d65c3c0
-
SHA1
7eaa6dffed7ebe043a6a32dacf0aa0bd549744f1
-
SHA256
47737c852a9b3e3ad1d9e6d96c3a6049dccb1c625b003e6423b163e6f850e99a
-
SHA512
24707e519a92090fe69ee3bbd7554c3a205a984c2db03fee3a0e6cfbfb94ed1d71a681ac4db0d031e18f1ea108549af79f3ce766f24eed8bb37f4b54ef27c775
-
SSDEEP
1536:/oh0n1CH0BVDo1raHXY5Ac/DG5E6wUs26L6DjtwrN3psO5:o21CHslo1raHmAci5EUoL6DRwrN3pF
Malware Config
Signatures
-
Suspicious behavior: GetForegroundWindowSpam 1 IoCs
Processes:
AcroRd32.exepid process 2836 AcroRd32.exe -
Suspicious use of SetWindowsHookEx 3 IoCs
Processes:
AcroRd32.exepid process 2836 AcroRd32.exe 2836 AcroRd32.exe 2836 AcroRd32.exe
Processes
-
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe"C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe" "C:\Users\Admin\AppData\Local\Temp\47737c852a9b3e3ad1d9e6d96c3a6049dccb1c625b003e6423b163e6f850e99a_NeikiAnalytics.pdf"1⤵
- Suspicious behavior: GetForegroundWindowSpam
- Suspicious use of SetWindowsHookEx
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Users\Admin\AppData\Roaming\Adobe\Acrobat\9.0\SharedDataEventsFilesize
3KB
MD5efb358bd43271ee9fa926c3a592b6ef7
SHA1e9baa05c24f33209e99b7271929ca94ea71ec840
SHA256d2b1d081f5b6c91372d1c68df424e4059ef0f540d9710338e765b1580438ad3c
SHA512afbed4156f271503a2baa642b386d3a4e48f9880b4a8f48a8b25f0a1cd6fadc382dd7e9d49511e1bfd7cfe91939a515c5b09c6301c4d3ad99e3b533579940a7a