General

  • Target

    2421172bcd12213259810c77c22dfe4acc88b4c2864d824129a7408c81a17b45_NeikiAnalytics.exe

  • Size

    91KB

  • Sample

    240630-3rwttssfmp

  • MD5

    03307fcbf19db033469d4053fdf081a0

  • SHA1

    65ca3b14789dfa5c80133c67a60bdfcb4d703b2d

  • SHA256

    2421172bcd12213259810c77c22dfe4acc88b4c2864d824129a7408c81a17b45

  • SHA512

    fdcce8df809a405a03bcd44b8ba1e1d9ab9fb54e12d23f1d1659b085fba85626eca14a4dc4f63a0ff28094d4300bf439cde43ba2305e82a907e3f4951c8b08bf

  • SSDEEP

    1536:9Q8hoOAesfYvcyjfS3H9yl8Q1pmdBcxedLxNDo73t6MlYqn+jMp9jb+5C/ihfJC:ymb3NkkiQ3mdBjFo73tvn+Yp9jb+5C/j

Malware Config

Targets

    • Target

      2421172bcd12213259810c77c22dfe4acc88b4c2864d824129a7408c81a17b45_NeikiAnalytics.exe

    • Size

      91KB

    • MD5

      03307fcbf19db033469d4053fdf081a0

    • SHA1

      65ca3b14789dfa5c80133c67a60bdfcb4d703b2d

    • SHA256

      2421172bcd12213259810c77c22dfe4acc88b4c2864d824129a7408c81a17b45

    • SHA512

      fdcce8df809a405a03bcd44b8ba1e1d9ab9fb54e12d23f1d1659b085fba85626eca14a4dc4f63a0ff28094d4300bf439cde43ba2305e82a907e3f4951c8b08bf

    • SSDEEP

      1536:9Q8hoOAesfYvcyjfS3H9yl8Q1pmdBcxedLxNDo73t6MlYqn+jMp9jb+5C/ihfJC:ymb3NkkiQ3mdBjFo73tvn+Yp9jb+5C/j

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks