General

  • Target

    6e16c1e10f4463d35f41fa6aad0fa93745e188223a892789280687a10a385a5c

  • Size

    129KB

  • Sample

    240629-2aw8la1fjj

  • MD5

    d8dc31caf6be0ba453a30b6e0f57a6a8

  • SHA1

    71e1b540eb0577b17f624ce94d4e42a202b92b0c

  • SHA256

    6e16c1e10f4463d35f41fa6aad0fa93745e188223a892789280687a10a385a5c

  • SHA512

    7deb6ba5541432478898cd44a3aac8224b7d4c70e1efc6dee2673886ce85120f60663101356025b293b7e219ba5bc650adf64ca2da9b945c1e1fa6e550a5f1da

  • SSDEEP

    3072:ymb3NkkiQ3mdBjFWXkj7afodnmm9Ao98h3dktX4/JL:n3C9BRW0j/tmm9nwytIV

Malware Config

Targets

    • Target

      6e16c1e10f4463d35f41fa6aad0fa93745e188223a892789280687a10a385a5c

    • Size

      129KB

    • MD5

      d8dc31caf6be0ba453a30b6e0f57a6a8

    • SHA1

      71e1b540eb0577b17f624ce94d4e42a202b92b0c

    • SHA256

      6e16c1e10f4463d35f41fa6aad0fa93745e188223a892789280687a10a385a5c

    • SHA512

      7deb6ba5541432478898cd44a3aac8224b7d4c70e1efc6dee2673886ce85120f60663101356025b293b7e219ba5bc650adf64ca2da9b945c1e1fa6e550a5f1da

    • SSDEEP

      3072:ymb3NkkiQ3mdBjFWXkj7afodnmm9Ao98h3dktX4/JL:n3C9BRW0j/tmm9nwytIV

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • UPX dump on OEP (original entry point)

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks