General

  • Target

    10b08b4d297b9ddb20f633ceb226dd42761b560ff1ff81d5eee0f01cc0201e0f_NeikiAnalytics.exe

  • Size

    195KB

  • Sample

    240630-v544csvcqr

  • MD5

    78ed03efe84e86b2bf83b7116d147310

  • SHA1

    9dccda4313511df103d8e4839e0e366a82a67202

  • SHA256

    10b08b4d297b9ddb20f633ceb226dd42761b560ff1ff81d5eee0f01cc0201e0f

  • SHA512

    4062c8c5e276c6503d30b16eafd9077957051796447f1ecc2b943c4c6bec9dd2e70fdec17b495ce930bfb764d6065663e62c4d51ebc4a9e395fe13e478ce9a7c

  • SSDEEP

    1536:gvQBeOGtrYSSsrc93UBIfdC67m6AJiqpfg3Cn/uiYs6Uo+:ghOm2sI93UufdC67ciifmCnmiYJUV

Malware Config

Targets

    • Target

      10b08b4d297b9ddb20f633ceb226dd42761b560ff1ff81d5eee0f01cc0201e0f_NeikiAnalytics.exe

    • Size

      195KB

    • MD5

      78ed03efe84e86b2bf83b7116d147310

    • SHA1

      9dccda4313511df103d8e4839e0e366a82a67202

    • SHA256

      10b08b4d297b9ddb20f633ceb226dd42761b560ff1ff81d5eee0f01cc0201e0f

    • SHA512

      4062c8c5e276c6503d30b16eafd9077957051796447f1ecc2b943c4c6bec9dd2e70fdec17b495ce930bfb764d6065663e62c4d51ebc4a9e395fe13e478ce9a7c

    • SSDEEP

      1536:gvQBeOGtrYSSsrc93UBIfdC67m6AJiqpfg3Cn/uiYs6Uo+:ghOm2sI93UufdC67ciifmCnmiYJUV

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks