General

  • Target

    8b5ae228086003cfcd0352e673de62ce353c9be4195b73c6734f0b3b2289bf90

  • Size

    465KB

  • Sample

    240630-313nqszcpg

  • MD5

    0c05f1a050d51133c7dd8b456affa340

  • SHA1

    a546d841713e92f50bbc943c106789e4f25890eb

  • SHA256

    8b5ae228086003cfcd0352e673de62ce353c9be4195b73c6734f0b3b2289bf90

  • SHA512

    f2a741b56af8cd957dcda14968c5ed04076680067f477d620573cf9a3c599cd058919df4b61653351bf26afac78ede131e3a8757b70b469d9ce7df55ba056fcc

  • SSDEEP

    12288:J4wFHoSTeR0oQRkay+eFp3IDvSbh5nPVP+OKaf1Ve:VeR0oykayRFp3lztP+OKaf1Ve

Malware Config

Targets

    • Target

      8b5ae228086003cfcd0352e673de62ce353c9be4195b73c6734f0b3b2289bf90

    • Size

      465KB

    • MD5

      0c05f1a050d51133c7dd8b456affa340

    • SHA1

      a546d841713e92f50bbc943c106789e4f25890eb

    • SHA256

      8b5ae228086003cfcd0352e673de62ce353c9be4195b73c6734f0b3b2289bf90

    • SHA512

      f2a741b56af8cd957dcda14968c5ed04076680067f477d620573cf9a3c599cd058919df4b61653351bf26afac78ede131e3a8757b70b469d9ce7df55ba056fcc

    • SSDEEP

      12288:J4wFHoSTeR0oQRkay+eFp3IDvSbh5nPVP+OKaf1Ve:VeR0oykayRFp3lztP+OKaf1Ve

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • UPX dump on OEP (original entry point)

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks