General

  • Target

    2f52e4a3c0de205e31f30f06b8e7f050_NeikiAnalytics.exe

  • Size

    384KB

  • Sample

    240604-fjv61aec97

  • MD5

    2f52e4a3c0de205e31f30f06b8e7f050

  • SHA1

    a87cf46ade386e8367be28682316ce909ed9fa64

  • SHA256

    a6a15a472cd5b373c2916884becd90d3a17ca9ec2210ece8e179665bdde7d79d

  • SHA512

    294caf6990e0e8d9dbe117d13bdb126bfa2680424c1e864587ed3e938f6cabcec02fbdb43abc4dad7267b3767da8209ca4927a8bf78ebb2b5d4d922ed8f5c818

  • SSDEEP

    6144:U9OAiuLWWXpui6yYPaIGckjh/xaSfBJKFbhD7sYQpui6yYPaIGck7/DiuoH3ygND:JiDpV6yYPMLnfBJKFbhDwBpV6yYP0riN

Malware Config

Targets

    • Target

      2f52e4a3c0de205e31f30f06b8e7f050_NeikiAnalytics.exe

    • Size

      384KB

    • MD5

      2f52e4a3c0de205e31f30f06b8e7f050

    • SHA1

      a87cf46ade386e8367be28682316ce909ed9fa64

    • SHA256

      a6a15a472cd5b373c2916884becd90d3a17ca9ec2210ece8e179665bdde7d79d

    • SHA512

      294caf6990e0e8d9dbe117d13bdb126bfa2680424c1e864587ed3e938f6cabcec02fbdb43abc4dad7267b3767da8209ca4927a8bf78ebb2b5d4d922ed8f5c818

    • SSDEEP

      6144:U9OAiuLWWXpui6yYPaIGckjh/xaSfBJKFbhD7sYQpui6yYPaIGck7/DiuoH3ygND:JiDpV6yYPMLnfBJKFbhDwBpV6yYP0riN

    • Adds autorun key to be loaded by Explorer.exe on startup

    • Malware Dropper & Backdoor - Berbew

      Berbew is a backdoor Trojan malware with capabilities to download and install a range of additional malicious software, such as other Trojans, ransomware, and cryptominers.

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks