General

  • Target

    785bcc362af6b8d5d7a9625117f9acd8c1114cf9b97a2f760878f3c8bc0d0759

  • Size

    207KB

  • Sample

    240629-2rkacsycmh

  • MD5

    ece27131e3255abfa32bfc8e5d5cea7e

  • SHA1

    5042be31ee8381e7403356f1e6942d2c9ffd8cac

  • SHA256

    785bcc362af6b8d5d7a9625117f9acd8c1114cf9b97a2f760878f3c8bc0d0759

  • SHA512

    f897d8c9bdf68f6a254a437b074db27006ee539d962c3a9451ef41f65cf61897a58566550accf64fb87bd435826444a2f21a3b45525c3dfdf05af95c0ca0431c

  • SSDEEP

    1536:PvQBeOGtrYSSsrc93UBIfdC67m6AJiqgT4+C2HVM1p6TQpCih2Qn:PhOm2sI93UufdC67ciJTU2HVS64h/

Malware Config

Targets

    • Target

      785bcc362af6b8d5d7a9625117f9acd8c1114cf9b97a2f760878f3c8bc0d0759

    • Size

      207KB

    • MD5

      ece27131e3255abfa32bfc8e5d5cea7e

    • SHA1

      5042be31ee8381e7403356f1e6942d2c9ffd8cac

    • SHA256

      785bcc362af6b8d5d7a9625117f9acd8c1114cf9b97a2f760878f3c8bc0d0759

    • SHA512

      f897d8c9bdf68f6a254a437b074db27006ee539d962c3a9451ef41f65cf61897a58566550accf64fb87bd435826444a2f21a3b45525c3dfdf05af95c0ca0431c

    • SSDEEP

      1536:PvQBeOGtrYSSsrc93UBIfdC67m6AJiqgT4+C2HVM1p6TQpCih2Qn:PhOm2sI93UufdC67ciJTU2HVS64h/

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • UPX dump on OEP (original entry point)

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks