General

  • Target

    491fc6143d8987ce5f395429657954f5a4655b202a7e3a7672430c1fa44007c3_NeikiAnalytics.exe

  • Size

    58KB

  • Sample

    240701-l16xqaycll

  • MD5

    5a2e422c5a90318ed7b69b7310d1d950

  • SHA1

    9001acba197208c9b0597f15358c87d206bf922b

  • SHA256

    491fc6143d8987ce5f395429657954f5a4655b202a7e3a7672430c1fa44007c3

  • SHA512

    ec06b1ca389864fee7ffa2ee33ad690098b806b7aa1bbffb5ebc31b2f14da86a7f380cd0e2d43d39534e9eee6bd987e070add58e71002d227780be013f9753bf

  • SSDEEP

    1536:9Q8hoOAesfYvcyjfS3H9yl8Q1pmdBcxedLxNDIF+AV:ymb3NkkiQ3mdBjFIF+AV

Malware Config

Targets

    • Target

      491fc6143d8987ce5f395429657954f5a4655b202a7e3a7672430c1fa44007c3_NeikiAnalytics.exe

    • Size

      58KB

    • MD5

      5a2e422c5a90318ed7b69b7310d1d950

    • SHA1

      9001acba197208c9b0597f15358c87d206bf922b

    • SHA256

      491fc6143d8987ce5f395429657954f5a4655b202a7e3a7672430c1fa44007c3

    • SHA512

      ec06b1ca389864fee7ffa2ee33ad690098b806b7aa1bbffb5ebc31b2f14da86a7f380cd0e2d43d39534e9eee6bd987e070add58e71002d227780be013f9753bf

    • SSDEEP

      1536:9Q8hoOAesfYvcyjfS3H9yl8Q1pmdBcxedLxNDIF+AV:ymb3NkkiQ3mdBjFIF+AV

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks