General

  • Target

    37c354b9349489ebf712396e59764d80_NeikiAnalytics.exe

  • Size

    128KB

  • Sample

    240604-g7gtysge84

  • MD5

    37c354b9349489ebf712396e59764d80

  • SHA1

    977210fc4d0ddf3af6568350a1a800819ed30b65

  • SHA256

    5c69ac63493c62decf3ab8d83333eb9c1b9b6a3f522685232bfb1a20a2fa6de6

  • SHA512

    b8faefc909606cbfc6f2aeac913938fae26d577985331fe94c7a6eb6062126016dfd5918de8bf1d34114803502d098589124a5f526005c96eb0d74b20e0aa9f2

  • SSDEEP

    1536:L4FBkp3O5aqsnpnTUngkCKEJpK9MyIB5BgRQD+XRfRa9HprmRfRJCLIXG:LSi+57YnTUnYXKHIB4eD+5wkpHxG

Malware Config

Targets

    • Target

      37c354b9349489ebf712396e59764d80_NeikiAnalytics.exe

    • Size

      128KB

    • MD5

      37c354b9349489ebf712396e59764d80

    • SHA1

      977210fc4d0ddf3af6568350a1a800819ed30b65

    • SHA256

      5c69ac63493c62decf3ab8d83333eb9c1b9b6a3f522685232bfb1a20a2fa6de6

    • SHA512

      b8faefc909606cbfc6f2aeac913938fae26d577985331fe94c7a6eb6062126016dfd5918de8bf1d34114803502d098589124a5f526005c96eb0d74b20e0aa9f2

    • SSDEEP

      1536:L4FBkp3O5aqsnpnTUngkCKEJpK9MyIB5BgRQD+XRfRa9HprmRfRJCLIXG:LSi+57YnTUnYXKHIB4eD+5wkpHxG

    • Adds autorun key to be loaded by Explorer.exe on startup

    • Malware Dropper & Backdoor - Berbew

      Berbew is a backdoor Trojan malware with capabilities to download and install a range of additional malicious software, such as other Trojans, ransomware, and cryptominers.

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks