General

  • Target

    2d28839d23a555dd9baa9a94df400fc0_NeikiAnalytics.exe

  • Size

    669KB

  • Sample

    240604-x6dc5sgh5w

  • MD5

    2d28839d23a555dd9baa9a94df400fc0

  • SHA1

    b6dc05926c47c4288a6d47301aed2b988fc124b8

  • SHA256

    4dcc76744ec04203874711329e184a24c9052e3c47635f72dab1b55ff91b0a84

  • SHA512

    cc8c4085350852b09a211762efc6400475dd9f54118c603b71689914383a7abaac613dfdb0f4baaa4734dfa32af307d2e6b904584d916bbb24f8d741bd499164

  • SSDEEP

    12288:2TFDnsDhf6fxeVKhMpQnqr+cI3a72LXrY6x46UbR/qYglMi:2TBnsDgfAchMpQnqrdX72LbY6x46uR/i

Malware Config

Targets

    • Target

      2d28839d23a555dd9baa9a94df400fc0_NeikiAnalytics.exe

    • Size

      669KB

    • MD5

      2d28839d23a555dd9baa9a94df400fc0

    • SHA1

      b6dc05926c47c4288a6d47301aed2b988fc124b8

    • SHA256

      4dcc76744ec04203874711329e184a24c9052e3c47635f72dab1b55ff91b0a84

    • SHA512

      cc8c4085350852b09a211762efc6400475dd9f54118c603b71689914383a7abaac613dfdb0f4baaa4734dfa32af307d2e6b904584d916bbb24f8d741bd499164

    • SSDEEP

      12288:2TFDnsDhf6fxeVKhMpQnqr+cI3a72LXrY6x46UbR/qYglMi:2TBnsDgfAchMpQnqrdX72LbY6x46uR/i

    • Adds autorun key to be loaded by Explorer.exe on startup

    • Malware Dropper & Backdoor - Berbew

      Berbew is a backdoor Trojan malware with capabilities to download and install a range of additional malicious software, such as other Trojans, ransomware, and cryptominers.

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks