General

  • Target

    2f7ddd55e548c9054c1c0460d3c3e3b0_NeikiAnalytics.exe

  • Size

    128KB

  • Sample

    240605-dglhnscc7x

  • MD5

    2f7ddd55e548c9054c1c0460d3c3e3b0

  • SHA1

    931c804d1d423c776bd4323821a6214b03b38fc6

  • SHA256

    12821ddb5cc1ced3b7dbd9c67601f11914e6d9e1b607e754a48bc91874cfae39

  • SHA512

    84d1381b810afec1b66ee3917da86b5039fd1f2d9fcf09ba6f9628382661111eea780ea2784d7267aea17204697d0171885758b6d2b8791dee6333a7ac9f8ec7

  • SSDEEP

    3072:B0iz3r0LGx0GO2/BhHmiImXJ2fYdV46nfPyxWhj8NCM/r:B0iz3IC0t4BhHmNEcYj9nhV8NCU

Malware Config

Targets

    • Target

      2f7ddd55e548c9054c1c0460d3c3e3b0_NeikiAnalytics.exe

    • Size

      128KB

    • MD5

      2f7ddd55e548c9054c1c0460d3c3e3b0

    • SHA1

      931c804d1d423c776bd4323821a6214b03b38fc6

    • SHA256

      12821ddb5cc1ced3b7dbd9c67601f11914e6d9e1b607e754a48bc91874cfae39

    • SHA512

      84d1381b810afec1b66ee3917da86b5039fd1f2d9fcf09ba6f9628382661111eea780ea2784d7267aea17204697d0171885758b6d2b8791dee6333a7ac9f8ec7

    • SSDEEP

      3072:B0iz3r0LGx0GO2/BhHmiImXJ2fYdV46nfPyxWhj8NCM/r:B0iz3IC0t4BhHmNEcYj9nhV8NCU

    • Adds autorun key to be loaded by Explorer.exe on startup

    • Malware Dropper & Backdoor - Berbew

      Berbew is a backdoor Trojan malware with capabilities to download and install a range of additional malicious software, such as other Trojans, ransomware, and cryptominers.

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks