General

  • Target

    4fb3fc0a450a50ed260ca28c9615a180_NeikiAnalytics.exe

  • Size

    94KB

  • Sample

    240605-l6v3eade89

  • MD5

    4fb3fc0a450a50ed260ca28c9615a180

  • SHA1

    a61ed7716c4b88db80786b3b1f2a5b5b7422c5e3

  • SHA256

    3c4a625877578dae97bdf3cd056c060a0aac9f14878c51aaa72ff6d2cb03f9f4

  • SHA512

    95273305398f88d41a22fbc7a3f39d84ffac1ab7cb4375a15ff3049c64544123e9223f96166ad6937d99e77300cb61f9b07882499c5287cfb02d34e1cd10b7c0

  • SSDEEP

    1536:Qwv9LDX6Vy45dbG40v/6RR7RR/RR7RR7RRVRRVRRVRRVhNRRRRRRRRRRCjRRvRRT:JF6V9DbRbWgjH6KU90uGimj1ieybvrx

Malware Config

Targets

    • Target

      4fb3fc0a450a50ed260ca28c9615a180_NeikiAnalytics.exe

    • Size

      94KB

    • MD5

      4fb3fc0a450a50ed260ca28c9615a180

    • SHA1

      a61ed7716c4b88db80786b3b1f2a5b5b7422c5e3

    • SHA256

      3c4a625877578dae97bdf3cd056c060a0aac9f14878c51aaa72ff6d2cb03f9f4

    • SHA512

      95273305398f88d41a22fbc7a3f39d84ffac1ab7cb4375a15ff3049c64544123e9223f96166ad6937d99e77300cb61f9b07882499c5287cfb02d34e1cd10b7c0

    • SSDEEP

      1536:Qwv9LDX6Vy45dbG40v/6RR7RR/RR7RR7RRVRRVRRVRRVhNRRRRRRRRRRCjRRvRRT:JF6V9DbRbWgjH6KU90uGimj1ieybvrx

    • Adds autorun key to be loaded by Explorer.exe on startup

    • Malware Dropper & Backdoor - Berbew

      Berbew is a backdoor Trojan malware with capabilities to download and install a range of additional malicious software, such as other Trojans, ransomware, and cryptominers.

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks