General

  • Target

    19e20d800fc938133685d775a369d10ddb8e4994be35d5c3e82f3d63ee273ccc_NeikiAnalytics.exe

  • Size

    74KB

  • Sample

    240630-z1ltfayfpj

  • MD5

    85bf13bfb7887de8ff7b2f2bdebb82a0

  • SHA1

    bd25be3627da94cf644017562900de63effa659a

  • SHA256

    19e20d800fc938133685d775a369d10ddb8e4994be35d5c3e82f3d63ee273ccc

  • SHA512

    c4d7f99148750a9d7f2d423328df3112fabf11808c64ceea0b62f27af7fa1addc331b313a60072b3df54f59210dab2489496d0a39fbff96c4c12c1dc89c92021

  • SSDEEP

    1536:IyfIcT9U1tPrgQvhLopacl1TsQk0NJP/PAjgas/3VUN0YWZPnouy8w:VfIS2vhLoz5sQkqgjg1YWZfoutw

Malware Config

Targets

    • Target

      19e20d800fc938133685d775a369d10ddb8e4994be35d5c3e82f3d63ee273ccc_NeikiAnalytics.exe

    • Size

      74KB

    • MD5

      85bf13bfb7887de8ff7b2f2bdebb82a0

    • SHA1

      bd25be3627da94cf644017562900de63effa659a

    • SHA256

      19e20d800fc938133685d775a369d10ddb8e4994be35d5c3e82f3d63ee273ccc

    • SHA512

      c4d7f99148750a9d7f2d423328df3112fabf11808c64ceea0b62f27af7fa1addc331b313a60072b3df54f59210dab2489496d0a39fbff96c4c12c1dc89c92021

    • SSDEEP

      1536:IyfIcT9U1tPrgQvhLopacl1TsQk0NJP/PAjgas/3VUN0YWZPnouy8w:VfIS2vhLoz5sQkqgjg1YWZfoutw

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • Deletes itself

    • Executes dropped EXE

    • Loads dropped DLL

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix ATT&CK v13

Tasks