General

  • Target

    112f9216f1f078351513f90863d8ea16c6ed9b3dd864ac8b634436ec85ee8d47_NeikiAnalytics.exe

  • Size

    138KB

  • Sample

    240630-wj3h3s1gpg

  • MD5

    38d55ca349801cc471b1a53f0b8f9a90

  • SHA1

    ae4a24916a4e5f75a297050fa9f2067e2da68764

  • SHA256

    112f9216f1f078351513f90863d8ea16c6ed9b3dd864ac8b634436ec85ee8d47

  • SHA512

    e48d26629c40cbe75860d6088b747e836e4208f8248916e8f3893f3268cc861cc67fb697503afe26cf15956bb92654d41f48f45f2bcb6e35ed16cf59a7c7d70f

  • SSDEEP

    3072:ymb3NkkiQ3mdBjFo73tvn+Yp9gBEpBGQfyw1SWMp2S:n3C9BRo7tvnJ9oEzpy1

Malware Config

Targets

    • Target

      112f9216f1f078351513f90863d8ea16c6ed9b3dd864ac8b634436ec85ee8d47_NeikiAnalytics.exe

    • Size

      138KB

    • MD5

      38d55ca349801cc471b1a53f0b8f9a90

    • SHA1

      ae4a24916a4e5f75a297050fa9f2067e2da68764

    • SHA256

      112f9216f1f078351513f90863d8ea16c6ed9b3dd864ac8b634436ec85ee8d47

    • SHA512

      e48d26629c40cbe75860d6088b747e836e4208f8248916e8f3893f3268cc861cc67fb697503afe26cf15956bb92654d41f48f45f2bcb6e35ed16cf59a7c7d70f

    • SSDEEP

      3072:ymb3NkkiQ3mdBjFo73tvn+Yp9gBEpBGQfyw1SWMp2S:n3C9BRo7tvnJ9oEzpy1

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks