General

  • Target

    329f9e90afa4bc33e63f98ff554b3c10_NeikiAnalytics.exe

  • Size

    94KB

  • Sample

    240604-f5g69sef2y

  • MD5

    329f9e90afa4bc33e63f98ff554b3c10

  • SHA1

    21128b8cc17034b4228fffc483e87807b511c01b

  • SHA256

    2e8f601825f4fb4594de13e91f28cf240f8e100a5f679018872765d13501b199

  • SHA512

    a87fa09ab4a92865789a8d41633e784dc906954e1b1b5e86346fee062b4271778494eb07547cd394777955788ca47881ea4879cf058aed680333afa290e27264

  • SSDEEP

    1536:MVjFZxpMqhJjILqvvWf3Lp5IZ78g76ddx6A2LdaIZTJ+7LhkiB0MPiKeEAgv:M5FHpMqDIsWjp5IyVx6xdaMU7uihJ5v

Malware Config

Targets

    • Target

      329f9e90afa4bc33e63f98ff554b3c10_NeikiAnalytics.exe

    • Size

      94KB

    • MD5

      329f9e90afa4bc33e63f98ff554b3c10

    • SHA1

      21128b8cc17034b4228fffc483e87807b511c01b

    • SHA256

      2e8f601825f4fb4594de13e91f28cf240f8e100a5f679018872765d13501b199

    • SHA512

      a87fa09ab4a92865789a8d41633e784dc906954e1b1b5e86346fee062b4271778494eb07547cd394777955788ca47881ea4879cf058aed680333afa290e27264

    • SSDEEP

      1536:MVjFZxpMqhJjILqvvWf3Lp5IZ78g76ddx6A2LdaIZTJ+7LhkiB0MPiKeEAgv:M5FHpMqDIsWjp5IyVx6xdaMU7uihJ5v

    • Adds autorun key to be loaded by Explorer.exe on startup

    • Malware Dropper & Backdoor - Berbew

      Berbew is a backdoor Trojan malware with capabilities to download and install a range of additional malicious software, such as other Trojans, ransomware, and cryptominers.

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks