General

  • Target

    23bb9eaf9592cce27c54a02255f6f48b3b3b60c6483d7258d4970ce6100438d3_NeikiAnalytics.exe

  • Size

    74KB

  • Sample

    240630-3m8mtssenq

  • MD5

    a274255d4c1a1a119182d457c1220330

  • SHA1

    b5b3143592fcc5e10a9cc839897882659f12dfbb

  • SHA256

    23bb9eaf9592cce27c54a02255f6f48b3b3b60c6483d7258d4970ce6100438d3

  • SHA512

    d99a91c8fe97af1c76386759f9747f3c730281b85f5cf2a78512dfcba8d31914937b33e16c63c2b3e6e610cb9418e8fde806c48d6aad62ff919f4be8310dece2

  • SSDEEP

    1536:9Q8hoOAesfYvcyjfS3H9yl8Q1pmdBcxedLxND0yUwcsbYsoam:ymb3NkkiQ3mdBjF0yjcsMsoam

Malware Config

Targets

    • Target

      23bb9eaf9592cce27c54a02255f6f48b3b3b60c6483d7258d4970ce6100438d3_NeikiAnalytics.exe

    • Size

      74KB

    • MD5

      a274255d4c1a1a119182d457c1220330

    • SHA1

      b5b3143592fcc5e10a9cc839897882659f12dfbb

    • SHA256

      23bb9eaf9592cce27c54a02255f6f48b3b3b60c6483d7258d4970ce6100438d3

    • SHA512

      d99a91c8fe97af1c76386759f9747f3c730281b85f5cf2a78512dfcba8d31914937b33e16c63c2b3e6e610cb9418e8fde806c48d6aad62ff919f4be8310dece2

    • SSDEEP

      1536:9Q8hoOAesfYvcyjfS3H9yl8Q1pmdBcxedLxND0yUwcsbYsoam:ymb3NkkiQ3mdBjF0yjcsMsoam

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks