General

  • Target

    3b6faa24e26e7dba5b5aa5576ce163936be9bf426b7fb5b437dae6fdebb079e2_NeikiAnalytics.exe

  • Size

    77KB

  • Sample

    240701-g2gxrs1fkj

  • MD5

    432497813803ba13e088c8e359daf490

  • SHA1

    dac19c1cd9f26ece6869b16f63b3b02c8ac0ca25

  • SHA256

    3b6faa24e26e7dba5b5aa5576ce163936be9bf426b7fb5b437dae6fdebb079e2

  • SHA512

    fda22f17225b4e1b743bf7d78b4c78d73d641624f138097c60f555474c0058544af6997221eb5f4fd664f26e77a9595647ad4db12e0efbf070b0f3cd3c0dcce4

  • SSDEEP

    1536:9vQBeOGtrYS3srx93UBWfwC6Ggnouy8PbhnyLFWoFLAxZhMDzE8mpcNo/:9hOmTsF93UYfwC6GIoutz5yLpOSDpo/

Malware Config

Targets

    • Target

      3b6faa24e26e7dba5b5aa5576ce163936be9bf426b7fb5b437dae6fdebb079e2_NeikiAnalytics.exe

    • Size

      77KB

    • MD5

      432497813803ba13e088c8e359daf490

    • SHA1

      dac19c1cd9f26ece6869b16f63b3b02c8ac0ca25

    • SHA256

      3b6faa24e26e7dba5b5aa5576ce163936be9bf426b7fb5b437dae6fdebb079e2

    • SHA512

      fda22f17225b4e1b743bf7d78b4c78d73d641624f138097c60f555474c0058544af6997221eb5f4fd664f26e77a9595647ad4db12e0efbf070b0f3cd3c0dcce4

    • SSDEEP

      1536:9vQBeOGtrYS3srx93UBWfwC6Ggnouy8PbhnyLFWoFLAxZhMDzE8mpcNo/:9hOmTsF93UYfwC6GIoutz5yLpOSDpo/

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks