General

  • Target

    4226392eb767a773373324b7352f39d9e439ea0f3d937912fb3868a3fdcb8429_NeikiAnalytics.exe

  • Size

    539KB

  • Sample

    240701-j1vtca1ake

  • MD5

    c10cb4a302fdd3423b08ac43b3b44db0

  • SHA1

    ec2081915b863ec0492706e5c18380053c2af84a

  • SHA256

    4226392eb767a773373324b7352f39d9e439ea0f3d937912fb3868a3fdcb8429

  • SHA512

    4dfa0cbc8ff934a90f98e46ba436b8a29b923e7635eb60ed2337cd59926a0909eed1031c52cdfeb75b18711dfbc6c6fc5ceef8e1125fd619f11db25b2d0c486c

  • SSDEEP

    12288:y4wFHoS3eFp3IDvSbh5nP+UbGTHoSouKs8N0u/D6vIZU:HFp3lzZbGa5soU

Malware Config

Targets

    • Target

      4226392eb767a773373324b7352f39d9e439ea0f3d937912fb3868a3fdcb8429_NeikiAnalytics.exe

    • Size

      539KB

    • MD5

      c10cb4a302fdd3423b08ac43b3b44db0

    • SHA1

      ec2081915b863ec0492706e5c18380053c2af84a

    • SHA256

      4226392eb767a773373324b7352f39d9e439ea0f3d937912fb3868a3fdcb8429

    • SHA512

      4dfa0cbc8ff934a90f98e46ba436b8a29b923e7635eb60ed2337cd59926a0909eed1031c52cdfeb75b18711dfbc6c6fc5ceef8e1125fd619f11db25b2d0c486c

    • SSDEEP

      12288:y4wFHoS3eFp3IDvSbh5nP+UbGTHoSouKs8N0u/D6vIZU:HFp3lzZbGa5soU

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks