General

  • Target

    48b6605ce634bb60ef3807b6b0e6d820_NeikiAnalytics.exe

  • Size

    844KB

  • Sample

    240605-h9wasshe7t

  • MD5

    48b6605ce634bb60ef3807b6b0e6d820

  • SHA1

    0d67b852f855fb87dee544c85822b4555bfb2ab9

  • SHA256

    79090e7eec8b67b17d5de89c5da4c4578bc68458a8fdd1f8594a6b17140f3db3

  • SHA512

    9c763e462b1868b13e9eb43c85ce1cb77df0a8305824a303e3fea97a7fa2878c9a5697fb495fc9b54c6735e50fba19a3f1873f5b9b8900b313807793b2218f40

  • SSDEEP

    24576:I+aH5W3Tnbc53cp6p5vihMpQnqrdX72LbY6x46uR/qYglMS:sH5W3TbGBihw+cdX2x46uhqllMS

Malware Config

Targets

    • Target

      48b6605ce634bb60ef3807b6b0e6d820_NeikiAnalytics.exe

    • Size

      844KB

    • MD5

      48b6605ce634bb60ef3807b6b0e6d820

    • SHA1

      0d67b852f855fb87dee544c85822b4555bfb2ab9

    • SHA256

      79090e7eec8b67b17d5de89c5da4c4578bc68458a8fdd1f8594a6b17140f3db3

    • SHA512

      9c763e462b1868b13e9eb43c85ce1cb77df0a8305824a303e3fea97a7fa2878c9a5697fb495fc9b54c6735e50fba19a3f1873f5b9b8900b313807793b2218f40

    • SSDEEP

      24576:I+aH5W3Tnbc53cp6p5vihMpQnqrdX72LbY6x46uR/qYglMS:sH5W3TbGBihw+cdX2x46uhqllMS

    • Adds autorun key to be loaded by Explorer.exe on startup

    • Malware Dropper & Backdoor - Berbew

      Berbew is a backdoor Trojan malware with capabilities to download and install a range of additional malicious software, such as other Trojans, ransomware, and cryptominers.

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks