General

  • Target

    4cb9590c199d3708ed896ca0265efad144f09c57291269e657130b5016568a1f_NeikiAnalytics.exe

  • Size

    88KB

  • Sample

    240701-m3erpaxfmb

  • MD5

    e7d8e985279f295269b4baf3ee06b090

  • SHA1

    a7c308658b01c19b3b251541a33bb94b407835e1

  • SHA256

    4cb9590c199d3708ed896ca0265efad144f09c57291269e657130b5016568a1f

  • SHA512

    831d8c5a61768d5193073ef1e07f4abac6f73408f15fef5275a142c1474e5ea33c6f1d8b928b44c547747782db504f0e7d64942d78772fcd86f2ef7a52a5d135

  • SSDEEP

    1536:9Q8hoOAesfYvcyjfS3H9yl8Q1pmdBcxedLxND+3T4+C2iJvRirE0DmoLZsO4YX:ymb3NkkiQ3mdBjF+3TU2iBRioSnZsTYX

Malware Config

Targets

    • Target

      4cb9590c199d3708ed896ca0265efad144f09c57291269e657130b5016568a1f_NeikiAnalytics.exe

    • Size

      88KB

    • MD5

      e7d8e985279f295269b4baf3ee06b090

    • SHA1

      a7c308658b01c19b3b251541a33bb94b407835e1

    • SHA256

      4cb9590c199d3708ed896ca0265efad144f09c57291269e657130b5016568a1f

    • SHA512

      831d8c5a61768d5193073ef1e07f4abac6f73408f15fef5275a142c1474e5ea33c6f1d8b928b44c547747782db504f0e7d64942d78772fcd86f2ef7a52a5d135

    • SSDEEP

      1536:9Q8hoOAesfYvcyjfS3H9yl8Q1pmdBcxedLxND+3T4+C2iJvRirE0DmoLZsO4YX:ymb3NkkiQ3mdBjF+3TU2iBRioSnZsTYX

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks