General

  • Target

    4536c74a4352c06a908c21c6608877245ac85fc256444abdc26a5271c71a084d_NeikiAnalytics.exe

  • Size

    88KB

  • Sample

    240701-kxgb8awcpm

  • MD5

    3611a91148859f861202167b62daa900

  • SHA1

    d02e017fc65d97924c20c9672967432edb8abc1f

  • SHA256

    4536c74a4352c06a908c21c6608877245ac85fc256444abdc26a5271c71a084d

  • SHA512

    b7c27face7c5b30a485c3572b70178c645843335df2563aec49caeeac95d20f4493df0f283a0bf564df143932c25f60e8a224fef0ae938c2d0c4cc14de253c55

  • SSDEEP

    1536:9Q8hoOAesfYvcyjfS3H9yl8Q1pmdBcxedLxND+3T4+C2iJvRirE0DmoLZsO4Yp:ymb3NkkiQ3mdBjF+3TU2iBRioSnZsTYp

Malware Config

Targets

    • Target

      4536c74a4352c06a908c21c6608877245ac85fc256444abdc26a5271c71a084d_NeikiAnalytics.exe

    • Size

      88KB

    • MD5

      3611a91148859f861202167b62daa900

    • SHA1

      d02e017fc65d97924c20c9672967432edb8abc1f

    • SHA256

      4536c74a4352c06a908c21c6608877245ac85fc256444abdc26a5271c71a084d

    • SHA512

      b7c27face7c5b30a485c3572b70178c645843335df2563aec49caeeac95d20f4493df0f283a0bf564df143932c25f60e8a224fef0ae938c2d0c4cc14de253c55

    • SSDEEP

      1536:9Q8hoOAesfYvcyjfS3H9yl8Q1pmdBcxedLxND+3T4+C2iJvRirE0DmoLZsO4Yp:ymb3NkkiQ3mdBjF+3TU2iBRioSnZsTYp

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks