General

  • Target

    296676abd5bf566947f9292a3d689bb0_NeikiAnalytics.exe

  • Size

    384KB

  • Sample

    240605-cgjteaba7v

  • MD5

    296676abd5bf566947f9292a3d689bb0

  • SHA1

    d276a3e6d1eaf4122fd64daeb2c12a04ac8f5294

  • SHA256

    773bd6f37bd8703faffedb3b5be6f248f11b41f73681e4131cfaab56a63bc703

  • SHA512

    768dcb1acb069caa45fa62e8ff41565e5c6cfceb29c4aea3b46f23a50b9f9572daca809be2b34c057eadd3012e63eb1816d503c6619b51fc4fbe8287d75d2928

  • SSDEEP

    6144:Ql6cUbD+nhLDEDCh10kEjiPISUOgW9X+hOGzC/NM:Ql6coinhLDEDnkmZzcukG2/

Malware Config

Targets

    • Target

      296676abd5bf566947f9292a3d689bb0_NeikiAnalytics.exe

    • Size

      384KB

    • MD5

      296676abd5bf566947f9292a3d689bb0

    • SHA1

      d276a3e6d1eaf4122fd64daeb2c12a04ac8f5294

    • SHA256

      773bd6f37bd8703faffedb3b5be6f248f11b41f73681e4131cfaab56a63bc703

    • SHA512

      768dcb1acb069caa45fa62e8ff41565e5c6cfceb29c4aea3b46f23a50b9f9572daca809be2b34c057eadd3012e63eb1816d503c6619b51fc4fbe8287d75d2928

    • SSDEEP

      6144:Ql6cUbD+nhLDEDCh10kEjiPISUOgW9X+hOGzC/NM:Ql6coinhLDEDnkmZzcukG2/

    Score
    10/10
    • Malware Dropper & Backdoor - Berbew

      Berbew is a backdoor Trojan malware with capabilities to download and install a range of additional malicious software, such as other Trojans, ransomware, and cryptominers.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks