General

  • Target

    557f0cd80984ce3997a5466e4eadb750_NeikiAnalytics.exe

  • Size

    3.7MB

  • Sample

    240605-p7xt6sgg89

  • MD5

    557f0cd80984ce3997a5466e4eadb750

  • SHA1

    f23d4e07dbf6e196a6e858350568a0c556e55fd4

  • SHA256

    77c90a70d56d40911bcbacb3b24f370d3f0151c95f0409627cd495c6de06a398

  • SHA512

    9d1a6075c21b564bbade370055632509cb8046b97a0a187761366cb02f8941ff77ed2eb3c6a687b6221e2e43bfc50c451e83d9d88ff79821a446c96f680dad18

  • SSDEEP

    98304:f+B6r6HaSHFaZRBEYyqmS2DiHPKQgmZ0aUgUjvha/4wzlF65T:f+paSHFaZRBEYyqmS2DiHPKQgwUgUjvJ

Malware Config

Targets

    • Target

      557f0cd80984ce3997a5466e4eadb750_NeikiAnalytics.exe

    • Size

      3.7MB

    • MD5

      557f0cd80984ce3997a5466e4eadb750

    • SHA1

      f23d4e07dbf6e196a6e858350568a0c556e55fd4

    • SHA256

      77c90a70d56d40911bcbacb3b24f370d3f0151c95f0409627cd495c6de06a398

    • SHA512

      9d1a6075c21b564bbade370055632509cb8046b97a0a187761366cb02f8941ff77ed2eb3c6a687b6221e2e43bfc50c451e83d9d88ff79821a446c96f680dad18

    • SSDEEP

      98304:f+B6r6HaSHFaZRBEYyqmS2DiHPKQgmZ0aUgUjvha/4wzlF65T:f+paSHFaZRBEYyqmS2DiHPKQgwUgUjvJ

    • Adds autorun key to be loaded by Explorer.exe on startup

    • Malware Dropper & Backdoor - Berbew

      Berbew is a backdoor Trojan malware with capabilities to download and install a range of additional malicious software, such as other Trojans, ransomware, and cryptominers.

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks