General

  • Target

    475fa78b8c634730c124b826dd74ded0_NeikiAnalytics.exe

  • Size

    109KB

  • Sample

    240605-hsydtshg63

  • MD5

    475fa78b8c634730c124b826dd74ded0

  • SHA1

    85cb22a50a598e880dcadcfcf45cb1c5b7544d2e

  • SHA256

    e097a62a1e399b34c5570d0385198afcbf8dc151f7d3fb745d39b8bd1a251771

  • SHA512

    c41bf9e62e0a0edf5ed756228cd36e9827dd36d6e4ecff4f2ed5fce0d3cd158ad1c6de804b400a5b450c79113011690fda64083fb4467025585c884c64e5c83d

  • SSDEEP

    3072:Ue9/9rR1f0GLXJ9vLCqwzBu1DjHLMVDqqkSp:UsJDxJ9Dwtu1DjrFqh

Malware Config

Targets

    • Target

      475fa78b8c634730c124b826dd74ded0_NeikiAnalytics.exe

    • Size

      109KB

    • MD5

      475fa78b8c634730c124b826dd74ded0

    • SHA1

      85cb22a50a598e880dcadcfcf45cb1c5b7544d2e

    • SHA256

      e097a62a1e399b34c5570d0385198afcbf8dc151f7d3fb745d39b8bd1a251771

    • SHA512

      c41bf9e62e0a0edf5ed756228cd36e9827dd36d6e4ecff4f2ed5fce0d3cd158ad1c6de804b400a5b450c79113011690fda64083fb4467025585c884c64e5c83d

    • SSDEEP

      3072:Ue9/9rR1f0GLXJ9vLCqwzBu1DjHLMVDqqkSp:UsJDxJ9Dwtu1DjrFqh

    • Adds autorun key to be loaded by Explorer.exe on startup

    • Malware Dropper & Backdoor - Berbew

      Berbew is a backdoor Trojan malware with capabilities to download and install a range of additional malicious software, such as other Trojans, ransomware, and cryptominers.

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks