General

  • Target

    4293ac6188831232844bd1ee97ce6870_NeikiAnalytics.exe

  • Size

    565KB

  • Sample

    240604-j3sf1aae2y

  • MD5

    4293ac6188831232844bd1ee97ce6870

  • SHA1

    6555cab827a63d259a43254047133aeca0044848

  • SHA256

    ac704bcc55b04f5ce907e2ca8e1787a96e4050c6a933fe0d37273e783ef05de9

  • SHA512

    083ab9f053ac4b3e6c8200f3bf59f7b9eb99c55eea282c68a846da412f1c88145feb2a45f234197a2237f549fba4feee9d71df907e0344c7fb5ab71493b1734e

  • SSDEEP

    12288:KPNItuFjAh//+zrWAIAqWim/+zrWAI5KF8OX:KytuFjAh/mvFimm09OX

Malware Config

Targets

    • Target

      4293ac6188831232844bd1ee97ce6870_NeikiAnalytics.exe

    • Size

      565KB

    • MD5

      4293ac6188831232844bd1ee97ce6870

    • SHA1

      6555cab827a63d259a43254047133aeca0044848

    • SHA256

      ac704bcc55b04f5ce907e2ca8e1787a96e4050c6a933fe0d37273e783ef05de9

    • SHA512

      083ab9f053ac4b3e6c8200f3bf59f7b9eb99c55eea282c68a846da412f1c88145feb2a45f234197a2237f549fba4feee9d71df907e0344c7fb5ab71493b1734e

    • SSDEEP

      12288:KPNItuFjAh//+zrWAIAqWim/+zrWAI5KF8OX:KytuFjAh/mvFimm09OX

    • Adds autorun key to be loaded by Explorer.exe on startup

    • Malware Dropper & Backdoor - Berbew

      Berbew is a backdoor Trojan malware with capabilities to download and install a range of additional malicious software, such as other Trojans, ransomware, and cryptominers.

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks