General

  • Target

    3755db1c38bae05a3a09dabe65bd7900_NeikiAnalytics.exe

  • Size

    109KB

  • Sample

    240604-g4bhrsgd86

  • MD5

    3755db1c38bae05a3a09dabe65bd7900

  • SHA1

    a25ef1b9b87af53529a6dada25501fc67df6b8f9

  • SHA256

    e23da3956d388a82f585fb53506d3c4b65a4debafce65ee98d26cd8d6e27eda1

  • SHA512

    e048f45afbf8984f0603af68dec9b2c278560ac4a5515b5a09e23b48553f97247f31ff2f43d0a0052b08fb16eb63651eb14d34759721ab39146b28c3cafbdcd7

  • SSDEEP

    3072:HpuHUixah6G2C+d8kJ9GLCqwzBu1DjHLMVDqqkSpR:Hpfixa+dJJ9Cwtu1DjrFqhz

Malware Config

Targets

    • Target

      3755db1c38bae05a3a09dabe65bd7900_NeikiAnalytics.exe

    • Size

      109KB

    • MD5

      3755db1c38bae05a3a09dabe65bd7900

    • SHA1

      a25ef1b9b87af53529a6dada25501fc67df6b8f9

    • SHA256

      e23da3956d388a82f585fb53506d3c4b65a4debafce65ee98d26cd8d6e27eda1

    • SHA512

      e048f45afbf8984f0603af68dec9b2c278560ac4a5515b5a09e23b48553f97247f31ff2f43d0a0052b08fb16eb63651eb14d34759721ab39146b28c3cafbdcd7

    • SSDEEP

      3072:HpuHUixah6G2C+d8kJ9GLCqwzBu1DjHLMVDqqkSpR:Hpfixa+dJJ9Cwtu1DjrFqhz

    • Adds autorun key to be loaded by Explorer.exe on startup

    • Malware Dropper & Backdoor - Berbew

      Berbew is a backdoor Trojan malware with capabilities to download and install a range of additional malicious software, such as other Trojans, ransomware, and cryptominers.

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks