General

  • Target

    3dad9bebb4b70f86a415649870afdd80_NeikiAnalytics.exe

  • Size

    164KB

  • Sample

    240604-h98k5ahh96

  • MD5

    3dad9bebb4b70f86a415649870afdd80

  • SHA1

    9bf893fe182c7a76760733417e5cb0f13f3445e8

  • SHA256

    adc1a4616b5c10536fc7c82681d61e79ebb12231b4e92057d9fc87f135a2bf3c

  • SHA512

    ea9f17d3e5be3cc50d62afba50316907ad133c2e07823a9dc98472906b17b053fadd8a974dd4deefb93e1bbe8cb018025e58338e7e28b00c6e1b1205a6d7eae0

  • SSDEEP

    3072:ig339jsCEZfF6zwKAg1sVUcE9j8bAn08uFafmHURHAVgnvedh6DRyU:ijCEZ96zwKAgyVvE58bAn08uF8YU8gnb

Malware Config

Targets

    • Target

      3dad9bebb4b70f86a415649870afdd80_NeikiAnalytics.exe

    • Size

      164KB

    • MD5

      3dad9bebb4b70f86a415649870afdd80

    • SHA1

      9bf893fe182c7a76760733417e5cb0f13f3445e8

    • SHA256

      adc1a4616b5c10536fc7c82681d61e79ebb12231b4e92057d9fc87f135a2bf3c

    • SHA512

      ea9f17d3e5be3cc50d62afba50316907ad133c2e07823a9dc98472906b17b053fadd8a974dd4deefb93e1bbe8cb018025e58338e7e28b00c6e1b1205a6d7eae0

    • SSDEEP

      3072:ig339jsCEZfF6zwKAg1sVUcE9j8bAn08uFafmHURHAVgnvedh6DRyU:ijCEZ96zwKAgyVvE58bAn08uF8YU8gnb

    • Adds autorun key to be loaded by Explorer.exe on startup

    • Malware Dropper & Backdoor - Berbew

      Berbew is a backdoor Trojan malware with capabilities to download and install a range of additional malicious software, such as other Trojans, ransomware, and cryptominers.

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks