General

  • Target

    5275b72dd94be854a84b4f459ecdeb0eaef34e8eb98129851ecd47b26094b72a_NeikiAnalytics.exe

  • Size

    106KB

  • Sample

    240701-ppt1kavflq

  • MD5

    d62550fade1871016b8574dc0ea5dc60

  • SHA1

    80bc06c7bbfe780d0de1a96504a7545e383f6e49

  • SHA256

    5275b72dd94be854a84b4f459ecdeb0eaef34e8eb98129851ecd47b26094b72a

  • SHA512

    45160dbe60de01ac982e79d0120e974ff41c7d6578dffddc92efeef67635145df91a11f9b6387f28b6f570f3508479a9f58dacac73704a61af59969c699374ee

  • SSDEEP

    1536:9Q8hoOAesfYvcyjfS3H9yl8Q1pmdBcxedLxNDoTNKDeS98hPUdHV7RNzfJN75:ymb3NkkiQ3mdBjFo5KDe88g1fD75

Malware Config

Targets

    • Target

      5275b72dd94be854a84b4f459ecdeb0eaef34e8eb98129851ecd47b26094b72a_NeikiAnalytics.exe

    • Size

      106KB

    • MD5

      d62550fade1871016b8574dc0ea5dc60

    • SHA1

      80bc06c7bbfe780d0de1a96504a7545e383f6e49

    • SHA256

      5275b72dd94be854a84b4f459ecdeb0eaef34e8eb98129851ecd47b26094b72a

    • SHA512

      45160dbe60de01ac982e79d0120e974ff41c7d6578dffddc92efeef67635145df91a11f9b6387f28b6f570f3508479a9f58dacac73704a61af59969c699374ee

    • SSDEEP

      1536:9Q8hoOAesfYvcyjfS3H9yl8Q1pmdBcxedLxNDoTNKDeS98hPUdHV7RNzfJN75:ymb3NkkiQ3mdBjFo5KDe88g1fD75

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks