General

  • Target

    accba40626d70379d9422fab13336760_NeikiAnalytics.exe

  • Size

    256KB

  • Sample

    240604-w6y46sfe6w

  • MD5

    accba40626d70379d9422fab13336760

  • SHA1

    5b31dc5ea31b8a19bddc6db282c1bd5b2cdb3bc5

  • SHA256

    9df64d5185a7ae4fb65e92eeabd57135a57d9187b999c592ae702fadcc690888

  • SHA512

    3acf13ea8c7e1f2af04cd8bab551103a46a26c1ff7696fe4f5db17f0fd2417e2ff0a3b62cb1f248cf1324d4162733950cd67fbf66e31a234a1f023fd0c39d6a8

  • SSDEEP

    6144:4wP68v04plWHjlpmmxieQbWGRdA6sQc/Yp7TVX3J/1awbWGRdA6sQc/YRU:X104GDlpJxifbWGRdA6sQhPbWGRdA6s5

Malware Config

Targets

    • Target

      accba40626d70379d9422fab13336760_NeikiAnalytics.exe

    • Size

      256KB

    • MD5

      accba40626d70379d9422fab13336760

    • SHA1

      5b31dc5ea31b8a19bddc6db282c1bd5b2cdb3bc5

    • SHA256

      9df64d5185a7ae4fb65e92eeabd57135a57d9187b999c592ae702fadcc690888

    • SHA512

      3acf13ea8c7e1f2af04cd8bab551103a46a26c1ff7696fe4f5db17f0fd2417e2ff0a3b62cb1f248cf1324d4162733950cd67fbf66e31a234a1f023fd0c39d6a8

    • SSDEEP

      6144:4wP68v04plWHjlpmmxieQbWGRdA6sQc/Yp7TVX3J/1awbWGRdA6sQc/YRU:X104GDlpJxifbWGRdA6sQhPbWGRdA6s5

    • Adds autorun key to be loaded by Explorer.exe on startup

    • Malware Dropper & Backdoor - Berbew

      Berbew is a backdoor Trojan malware with capabilities to download and install a range of additional malicious software, such as other Trojans, ransomware, and cryptominers.

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks