General

  • Target

    483a72b7874a17167dbcff1eec2d65d1d9f15b405de41b2863e9d677ae2e10af_NeikiAnalytics.exe

  • Size

    134KB

  • Sample

    240701-lqjdnsvald

  • MD5

    691fa633bdc21f641ea3196d809ca0a0

  • SHA1

    73b6ae277413dd1509c2b2e3dd1545c0adcf5c22

  • SHA256

    483a72b7874a17167dbcff1eec2d65d1d9f15b405de41b2863e9d677ae2e10af

  • SHA512

    929fd5786149f57c0356e4c2b8709da18d8b463bad4eccfc85162e43d3fdb4a39e10603db05b487640119d50c7e6c2b14ef52171a76dee7fded09f32fd4bff84

  • SSDEEP

    3072:ymb3NkkiQ3mdBjFo73HUoMsAbrF3BTUwFB:n3C9BRo7HCsAbhxYo

Malware Config

Targets

    • Target

      483a72b7874a17167dbcff1eec2d65d1d9f15b405de41b2863e9d677ae2e10af_NeikiAnalytics.exe

    • Size

      134KB

    • MD5

      691fa633bdc21f641ea3196d809ca0a0

    • SHA1

      73b6ae277413dd1509c2b2e3dd1545c0adcf5c22

    • SHA256

      483a72b7874a17167dbcff1eec2d65d1d9f15b405de41b2863e9d677ae2e10af

    • SHA512

      929fd5786149f57c0356e4c2b8709da18d8b463bad4eccfc85162e43d3fdb4a39e10603db05b487640119d50c7e6c2b14ef52171a76dee7fded09f32fd4bff84

    • SSDEEP

      3072:ymb3NkkiQ3mdBjFo73HUoMsAbrF3BTUwFB:n3C9BRo7HCsAbhxYo

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks