General

  • Target

    6a8a6e30de4af5d9f0abd9ca510fa6111100d9a54faae2aecac6a4e866a1db23

  • Size

    93KB

  • Sample

    240630-2hl3la1dmp

  • MD5

    2758aacdc92bcb3bab38eb6d931deed1

  • SHA1

    073484ee69c1338ed41187cc0069053077bf8e29

  • SHA256

    6a8a6e30de4af5d9f0abd9ca510fa6111100d9a54faae2aecac6a4e866a1db23

  • SHA512

    f488ef36e6e471a04a3fcfb203c5f61e6de0827694fa8366b90e32a0664329382915a6999ea17edec113ab824fcd111448e34d067db15bd021d77614116569fb

  • SSDEEP

    1536:9Q8hoOAesfYvcyjfS3H9yl8Q1pmdBcxedLxNDInWeNCYGyA2R7JxJAg8dtG:ymb3NkkiQ3mdBjFIWeFGyAsJAg2G

Malware Config

Targets

    • Target

      6a8a6e30de4af5d9f0abd9ca510fa6111100d9a54faae2aecac6a4e866a1db23

    • Size

      93KB

    • MD5

      2758aacdc92bcb3bab38eb6d931deed1

    • SHA1

      073484ee69c1338ed41187cc0069053077bf8e29

    • SHA256

      6a8a6e30de4af5d9f0abd9ca510fa6111100d9a54faae2aecac6a4e866a1db23

    • SHA512

      f488ef36e6e471a04a3fcfb203c5f61e6de0827694fa8366b90e32a0664329382915a6999ea17edec113ab824fcd111448e34d067db15bd021d77614116569fb

    • SSDEEP

      1536:9Q8hoOAesfYvcyjfS3H9yl8Q1pmdBcxedLxNDInWeNCYGyA2R7JxJAg8dtG:ymb3NkkiQ3mdBjFIWeFGyAsJAg2G

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • UPX dump on OEP (original entry point)

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks