General

  • Target

    56105ef24748ac026cebb07f5431ba595e4904ae238a706475777332ea1e2a7c

  • Size

    72KB

  • Sample

    240630-1kd94awfla

  • MD5

    00f70901dffc1dac0daef4e8de2da184

  • SHA1

    9ce5b55a0f4716e03c0ed77a3d6e460d80b73721

  • SHA256

    56105ef24748ac026cebb07f5431ba595e4904ae238a706475777332ea1e2a7c

  • SHA512

    b9990e42576a8fb77fd2d35caed4a88c133ca020da453fd083662e8a50f95d6d8294cac9460bc6a25a91db4781f0e1cf24f6a32d208aff02caa7b91a606de547

  • SSDEEP

    1536:9Q8hoOAesfYvcyjfS3H9yl8Q1pmdBcxedLxNDIgUVyiAnfe2:ymb3NkkiQ3mdBjFIgUEBe2

Malware Config

Targets

    • Target

      56105ef24748ac026cebb07f5431ba595e4904ae238a706475777332ea1e2a7c

    • Size

      72KB

    • MD5

      00f70901dffc1dac0daef4e8de2da184

    • SHA1

      9ce5b55a0f4716e03c0ed77a3d6e460d80b73721

    • SHA256

      56105ef24748ac026cebb07f5431ba595e4904ae238a706475777332ea1e2a7c

    • SHA512

      b9990e42576a8fb77fd2d35caed4a88c133ca020da453fd083662e8a50f95d6d8294cac9460bc6a25a91db4781f0e1cf24f6a32d208aff02caa7b91a606de547

    • SSDEEP

      1536:9Q8hoOAesfYvcyjfS3H9yl8Q1pmdBcxedLxNDIgUVyiAnfe2:ymb3NkkiQ3mdBjFIgUEBe2

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • UPX dump on OEP (original entry point)

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks