General

  • Target

    24e01108e10e901cabd1f535de443dcdad0b8905c63848c9a7353bc5dbaa9ffa_NeikiAnalytics.exe

  • Size

    279KB

  • Sample

    240630-3zpqgsshlp

  • MD5

    8ef64e3d0223ca80c426291b0e2dc390

  • SHA1

    f18998e813d8118c9241158f6b4efaa0a7407617

  • SHA256

    24e01108e10e901cabd1f535de443dcdad0b8905c63848c9a7353bc5dbaa9ffa

  • SHA512

    49a207c0708aa98101d1314f470f510df95f52e4c7af039f7bcbf59d64f96ceb780f4276f61f1b13af143506c8e6a1e4e1f0f11d0643e5d1f37c73142ba40d7d

  • SSDEEP

    6144:n3C9BRIG0asYFm71m8+GdkB9yMu7VvemWc:n3C9uYA71kSMun

Malware Config

Targets

    • Target

      24e01108e10e901cabd1f535de443dcdad0b8905c63848c9a7353bc5dbaa9ffa_NeikiAnalytics.exe

    • Size

      279KB

    • MD5

      8ef64e3d0223ca80c426291b0e2dc390

    • SHA1

      f18998e813d8118c9241158f6b4efaa0a7407617

    • SHA256

      24e01108e10e901cabd1f535de443dcdad0b8905c63848c9a7353bc5dbaa9ffa

    • SHA512

      49a207c0708aa98101d1314f470f510df95f52e4c7af039f7bcbf59d64f96ceb780f4276f61f1b13af143506c8e6a1e4e1f0f11d0643e5d1f37c73142ba40d7d

    • SSDEEP

      6144:n3C9BRIG0asYFm71m8+GdkB9yMu7VvemWc:n3C9uYA71kSMun

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks