General

  • Target

    42104c4d4c80d2c1f43d4970258e9f825a3801a974825bb4eb3057fcfd8ffd23_NeikiAnalytics.exe

  • Size

    369KB

  • Sample

    240701-jz7frazhrb

  • MD5

    f7d9bd83fc2c718004da457608233b30

  • SHA1

    ae87b099dceacad02112b552be64c0ced875bd20

  • SHA256

    42104c4d4c80d2c1f43d4970258e9f825a3801a974825bb4eb3057fcfd8ffd23

  • SHA512

    fd7c54cdfc8e12e5ef81f268f8975b848515046e7ea8f016241f8ca3bc2f62d60619168679c6e20cd2d9c30f3e8a054ba33cbccb538dda338d00ddd263dd58ea

  • SSDEEP

    3072:ymb3NkkiQ3mdBjFo73tvn+Yp9FrHSwh/c/hdTWGIaxJ8TN005pWmjVwdSsy0p:n3C9BRo7tvnJ9Fywhk/T7xyTpShZVp

Malware Config

Targets

    • Target

      42104c4d4c80d2c1f43d4970258e9f825a3801a974825bb4eb3057fcfd8ffd23_NeikiAnalytics.exe

    • Size

      369KB

    • MD5

      f7d9bd83fc2c718004da457608233b30

    • SHA1

      ae87b099dceacad02112b552be64c0ced875bd20

    • SHA256

      42104c4d4c80d2c1f43d4970258e9f825a3801a974825bb4eb3057fcfd8ffd23

    • SHA512

      fd7c54cdfc8e12e5ef81f268f8975b848515046e7ea8f016241f8ca3bc2f62d60619168679c6e20cd2d9c30f3e8a054ba33cbccb538dda338d00ddd263dd58ea

    • SSDEEP

      3072:ymb3NkkiQ3mdBjFo73tvn+Yp9FrHSwh/c/hdTWGIaxJ8TN005pWmjVwdSsy0p:n3C9BRo7tvnJ9Fywhk/T7xyTpShZVp

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks