General

  • Target

    24c14db11c563a6715feb41d0f82d62ac135f8c34628dd7baa2b6a3d6f912276_NeikiAnalytics.exe

  • Size

    213KB

  • Sample

    240630-3yqw6ashjr

  • MD5

    8b2200fc4011363d4c702945f4731970

  • SHA1

    7959795a4000946d033829a8290e23980792e94a

  • SHA256

    24c14db11c563a6715feb41d0f82d62ac135f8c34628dd7baa2b6a3d6f912276

  • SHA512

    82f9fd5b6f00625b805e1268b8791cda2c7fbef1f8ac5f97c63e94f9f29904867a8cef200ad7e84987c4ebbfa0243cde23031e5818efe78f943bc933eeb69ca7

  • SSDEEP

    3072:mwZFBG7Gt5LQpL17tCAZbpQvKgMYbKXonUmeWxgFCg/0aDaBRghz:msFY7c5LuBUKbGw/SxhScUDaU

Malware Config

Targets

    • Target

      24c14db11c563a6715feb41d0f82d62ac135f8c34628dd7baa2b6a3d6f912276_NeikiAnalytics.exe

    • Size

      213KB

    • MD5

      8b2200fc4011363d4c702945f4731970

    • SHA1

      7959795a4000946d033829a8290e23980792e94a

    • SHA256

      24c14db11c563a6715feb41d0f82d62ac135f8c34628dd7baa2b6a3d6f912276

    • SHA512

      82f9fd5b6f00625b805e1268b8791cda2c7fbef1f8ac5f97c63e94f9f29904867a8cef200ad7e84987c4ebbfa0243cde23031e5818efe78f943bc933eeb69ca7

    • SSDEEP

      3072:mwZFBG7Gt5LQpL17tCAZbpQvKgMYbKXonUmeWxgFCg/0aDaBRghz:msFY7c5LuBUKbGw/SxhScUDaU

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks