General

  • Target

    490824f4a6f961b730b8d416cdc7681a369c9be94fea392d564af6f95a840570_NeikiAnalytics.exe

  • Size

    368KB

  • Sample

    240701-l1h6naveka

  • MD5

    00bb4bbc69ab96227cb9b4ad7e376010

  • SHA1

    a4e8af01ebc6bb78beda9ca256da8ab4fa8937d0

  • SHA256

    490824f4a6f961b730b8d416cdc7681a369c9be94fea392d564af6f95a840570

  • SHA512

    85f8a185b1cb000447a6250150343147c8fd2b835633269b31fe8a98400fc3a49530e6f15b83c084ad2f42e11bcabc226a476acd984966ba088da532a58a1c4c

  • SSDEEP

    3072:ymb3NkkiQ3mdBjFo73tvn+Yp9FrHSwh/c/hdTWGIaxJ8TN005pWmjVwdSsyu:n3C9BRo7tvnJ9Fywhk/T7xyTpShZH

Malware Config

Targets

    • Target

      490824f4a6f961b730b8d416cdc7681a369c9be94fea392d564af6f95a840570_NeikiAnalytics.exe

    • Size

      368KB

    • MD5

      00bb4bbc69ab96227cb9b4ad7e376010

    • SHA1

      a4e8af01ebc6bb78beda9ca256da8ab4fa8937d0

    • SHA256

      490824f4a6f961b730b8d416cdc7681a369c9be94fea392d564af6f95a840570

    • SHA512

      85f8a185b1cb000447a6250150343147c8fd2b835633269b31fe8a98400fc3a49530e6f15b83c084ad2f42e11bcabc226a476acd984966ba088da532a58a1c4c

    • SSDEEP

      3072:ymb3NkkiQ3mdBjFo73tvn+Yp9FrHSwh/c/hdTWGIaxJ8TN005pWmjVwdSsyu:n3C9BRo7tvnJ9Fywhk/T7xyTpShZH

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks