General

  • Target

    1a36a2c531315405400c6b37cc84bb816a474e0dd548e81756cba47863d0dd25_NeikiAnalytics.exe

  • Size

    74KB

  • Sample

    240630-z4mvxaygml

  • MD5

    a928a15088d1523d6568c0e6d1ee5d20

  • SHA1

    85ab6348c9e8a3930f79edd0ce859bdec6b4e8ff

  • SHA256

    1a36a2c531315405400c6b37cc84bb816a474e0dd548e81756cba47863d0dd25

  • SHA512

    326205907ae97fe52d2c39ffdc291ce92b76c2960443f948a0638752ba0c71b9f99fb203b43c5e8e5d0e25bb5b2529975c421026d4a3f22514196a681837d01f

  • SSDEEP

    1536:9Q8hoOAesfYvcyjfS3H9yl8Q1pmdBcxedLxNDIfv7+afCD+QsQbKQPEJ:ymb3NkkiQ3mdBjFIfvTfCD+HlQcJ

Malware Config

Targets

    • Target

      1a36a2c531315405400c6b37cc84bb816a474e0dd548e81756cba47863d0dd25_NeikiAnalytics.exe

    • Size

      74KB

    • MD5

      a928a15088d1523d6568c0e6d1ee5d20

    • SHA1

      85ab6348c9e8a3930f79edd0ce859bdec6b4e8ff

    • SHA256

      1a36a2c531315405400c6b37cc84bb816a474e0dd548e81756cba47863d0dd25

    • SHA512

      326205907ae97fe52d2c39ffdc291ce92b76c2960443f948a0638752ba0c71b9f99fb203b43c5e8e5d0e25bb5b2529975c421026d4a3f22514196a681837d01f

    • SSDEEP

      1536:9Q8hoOAesfYvcyjfS3H9yl8Q1pmdBcxedLxNDIfv7+afCD+QsQbKQPEJ:ymb3NkkiQ3mdBjFIfvTfCD+HlQcJ

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks