General

  • Target

    07a0c2b53fb46b5386f6e7bd82fe3be0_NeikiAnalytics.exe

  • Size

    199KB

  • Sample

    240604-yee84ahc4t

  • MD5

    07a0c2b53fb46b5386f6e7bd82fe3be0

  • SHA1

    c659d6d08fecdd15aef0356a38ad84ad1fc8c86b

  • SHA256

    9ee4c5e093be62d8d2a068f054b028800e307015046a404da0c54a567994ad89

  • SHA512

    fd60729b2f059f0b4718f700581320de783e733e024a45df8950d3c93d4ec3acd080598bb88424a671ae8a5e82662719c49767207efa89c1740c13ae0c4f04cd

  • SSDEEP

    6144:NiM6NOkSZSCZj81+jq4peBK034YOmFz1h:j6NwZSCG1+jheBbOmFxh

Malware Config

Targets

    • Target

      07a0c2b53fb46b5386f6e7bd82fe3be0_NeikiAnalytics.exe

    • Size

      199KB

    • MD5

      07a0c2b53fb46b5386f6e7bd82fe3be0

    • SHA1

      c659d6d08fecdd15aef0356a38ad84ad1fc8c86b

    • SHA256

      9ee4c5e093be62d8d2a068f054b028800e307015046a404da0c54a567994ad89

    • SHA512

      fd60729b2f059f0b4718f700581320de783e733e024a45df8950d3c93d4ec3acd080598bb88424a671ae8a5e82662719c49767207efa89c1740c13ae0c4f04cd

    • SSDEEP

      6144:NiM6NOkSZSCZj81+jq4peBK034YOmFz1h:j6NwZSCG1+jheBbOmFxh

    • Adds autorun key to be loaded by Explorer.exe on startup

    • Malware Dropper & Backdoor - Berbew

      Berbew is a backdoor Trojan malware with capabilities to download and install a range of additional malicious software, such as other Trojans, ransomware, and cryptominers.

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks