General

  • Target

    4adda7603d9073f6bae4ef1690769089d979cffe5164ae02f60bd7a691178ba5_NeikiAnalytics.exe

  • Size

    124KB

  • Sample

    240701-mh535swdrf

  • MD5

    9d1996b74cf71d1abeb88e55ab36ec00

  • SHA1

    44b2fe1b274ee4f120ea37996bbc5edcad4c695c

  • SHA256

    4adda7603d9073f6bae4ef1690769089d979cffe5164ae02f60bd7a691178ba5

  • SHA512

    64e414c2eb62f2db146831de4365014d9710baec4a97a39e169001c8cde3916a4a10c2d7e5e0828687fd672659266e234ad22ebf75c352d4747e1a1734fc3730

  • SSDEEP

    3072:9hOmTsF93UYfwC6GIoutz5yLpcgDE4JgY0nUp:9cm4FmowdHoS49oUp

Malware Config

Targets

    • Target

      4adda7603d9073f6bae4ef1690769089d979cffe5164ae02f60bd7a691178ba5_NeikiAnalytics.exe

    • Size

      124KB

    • MD5

      9d1996b74cf71d1abeb88e55ab36ec00

    • SHA1

      44b2fe1b274ee4f120ea37996bbc5edcad4c695c

    • SHA256

      4adda7603d9073f6bae4ef1690769089d979cffe5164ae02f60bd7a691178ba5

    • SHA512

      64e414c2eb62f2db146831de4365014d9710baec4a97a39e169001c8cde3916a4a10c2d7e5e0828687fd672659266e234ad22ebf75c352d4747e1a1734fc3730

    • SSDEEP

      3072:9hOmTsF93UYfwC6GIoutz5yLpcgDE4JgY0nUp:9cm4FmowdHoS49oUp

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks