General

  • Target

    4b86f512d87535cc61f4473d969ff760_NeikiAnalytics.exe

  • Size

    128KB

  • Sample

    240605-kbzaxaag71

  • MD5

    4b86f512d87535cc61f4473d969ff760

  • SHA1

    0e2a72f97862790f3fdbaa27f7aae36cc145799f

  • SHA256

    7ffec294dbaff68cd9fbcfd01774f35f2e2764d619acfa37611d5bbcf7dcee8c

  • SHA512

    71f7a5d66a76df0345b56f4d2805b7fac643daa132793a2bf1491ef7c9f0b0aba71fa6d4bab29df71b09960c73534f0e9d4df0b39b5ca31f86528786714c140d

  • SSDEEP

    3072:8FDHm1A8w9Qxfmy4k4FHCCXimW2wS7IrHrYj:8FT8wWqCCSmHwMOHm

Malware Config

Targets

    • Target

      4b86f512d87535cc61f4473d969ff760_NeikiAnalytics.exe

    • Size

      128KB

    • MD5

      4b86f512d87535cc61f4473d969ff760

    • SHA1

      0e2a72f97862790f3fdbaa27f7aae36cc145799f

    • SHA256

      7ffec294dbaff68cd9fbcfd01774f35f2e2764d619acfa37611d5bbcf7dcee8c

    • SHA512

      71f7a5d66a76df0345b56f4d2805b7fac643daa132793a2bf1491ef7c9f0b0aba71fa6d4bab29df71b09960c73534f0e9d4df0b39b5ca31f86528786714c140d

    • SSDEEP

      3072:8FDHm1A8w9Qxfmy4k4FHCCXimW2wS7IrHrYj:8FT8wWqCCSmHwMOHm

    • Adds autorun key to be loaded by Explorer.exe on startup

    • Malware Dropper & Backdoor - Berbew

      Berbew is a backdoor Trojan malware with capabilities to download and install a range of additional malicious software, such as other Trojans, ransomware, and cryptominers.

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks