General

  • Target

    c925cae083d744c769e5596798f655ce19bb26bde82f2160e42b11016587e43d

  • Size

    13.6MB

  • Sample

    240630-3epvrayfjd

  • MD5

    323934027c61a9127afe56a0a4f8613b

  • SHA1

    24539658dcfaa6acccc15e332d3e3bf9d927d7e7

  • SHA256

    c925cae083d744c769e5596798f655ce19bb26bde82f2160e42b11016587e43d

  • SHA512

    d228b4b7979908aea70d84270a08ec4b169da2288b9c563fdebfaf5975887640556a2e575e7be2378d90cb04daf1f29d6b53116cc0a111c694e8c378087fc08d

  • SSDEEP

    393216:myC9rb34jrkwmKRcl+bIjo2MXmziyjSWL:HC9rbIjYwNRt+rMXm+y

Malware Config

Targets

    • Target

      c925cae083d744c769e5596798f655ce19bb26bde82f2160e42b11016587e43d

    • Size

      13.6MB

    • MD5

      323934027c61a9127afe56a0a4f8613b

    • SHA1

      24539658dcfaa6acccc15e332d3e3bf9d927d7e7

    • SHA256

      c925cae083d744c769e5596798f655ce19bb26bde82f2160e42b11016587e43d

    • SHA512

      d228b4b7979908aea70d84270a08ec4b169da2288b9c563fdebfaf5975887640556a2e575e7be2378d90cb04daf1f29d6b53116cc0a111c694e8c378087fc08d

    • SSDEEP

      393216:myC9rb34jrkwmKRcl+bIjo2MXmziyjSWL:HC9rbIjYwNRt+rMXm+y

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • ACProtect 1.3x - 1.4x DLL software

      Detects file using ACProtect software.

    • Executes dropped EXE

    • Loads dropped DLL

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix ATT&CK v13

Tasks