General

  • Target

    302728774051c2cc38334fcaaae8356d8175eead8f866daf02c35dad75e21228_NeikiAnalytics.exe

  • Size

    79KB

  • Sample

    240701-dd46lstfrc

  • MD5

    fbed864e8ab53eeb5d32483a3ce11630

  • SHA1

    65f0b59238f8b7564fd5b78657ccdf702cac0f82

  • SHA256

    302728774051c2cc38334fcaaae8356d8175eead8f866daf02c35dad75e21228

  • SHA512

    8dcdf65b854adfbe9c5d01f4893794a9d8f503df7f94441a646be3539f96baeb775353145104007815e4b4b91ac871e6fdb6e1bc5f2713159068d76ce144cbd0

  • SSDEEP

    1536:9Q8hoOAesfYvcyjfS3H9yl8Q1pmdBcxedLxNDIIpIo60L9QrrA89T:ymb3NkkiQ3mdBjFIIp9L9QrrA8B

Malware Config

Targets

    • Target

      302728774051c2cc38334fcaaae8356d8175eead8f866daf02c35dad75e21228_NeikiAnalytics.exe

    • Size

      79KB

    • MD5

      fbed864e8ab53eeb5d32483a3ce11630

    • SHA1

      65f0b59238f8b7564fd5b78657ccdf702cac0f82

    • SHA256

      302728774051c2cc38334fcaaae8356d8175eead8f866daf02c35dad75e21228

    • SHA512

      8dcdf65b854adfbe9c5d01f4893794a9d8f503df7f94441a646be3539f96baeb775353145104007815e4b4b91ac871e6fdb6e1bc5f2713159068d76ce144cbd0

    • SSDEEP

      1536:9Q8hoOAesfYvcyjfS3H9yl8Q1pmdBcxedLxNDIIpIo60L9QrrA89T:ymb3NkkiQ3mdBjFIIp9L9QrrA8B

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks