General

  • Target

    9badc0fba0845eab9b260ca0f740aea24797de6d84a59760a53adf55bc65a3d7

  • Size

    139KB

  • Sample

    240630-ak7njatdql

  • MD5

    9412d21ce409ff838e2179a9a87f2d63

  • SHA1

    1a2bc322917a03e9b79a29cc8485fda82b66221b

  • SHA256

    9badc0fba0845eab9b260ca0f740aea24797de6d84a59760a53adf55bc65a3d7

  • SHA512

    972af71008e00d2c8a30cf8b5afb47d86482de834e65e5713eacbfbaf15b0149cc87bd66594a046b725341e11cb3961fce4ab3e29c1f160b36b444be6486fba2

  • SSDEEP

    3072:khOmTsF93UYfwC6GIoutpYcvrqrE66kropO6BfDKPeGrRZ:kcm4FmowdHoSphraHcpOaKHj

Malware Config

Targets

    • Target

      9badc0fba0845eab9b260ca0f740aea24797de6d84a59760a53adf55bc65a3d7

    • Size

      139KB

    • MD5

      9412d21ce409ff838e2179a9a87f2d63

    • SHA1

      1a2bc322917a03e9b79a29cc8485fda82b66221b

    • SHA256

      9badc0fba0845eab9b260ca0f740aea24797de6d84a59760a53adf55bc65a3d7

    • SHA512

      972af71008e00d2c8a30cf8b5afb47d86482de834e65e5713eacbfbaf15b0149cc87bd66594a046b725341e11cb3961fce4ab3e29c1f160b36b444be6486fba2

    • SSDEEP

      3072:khOmTsF93UYfwC6GIoutpYcvrqrE66kropO6BfDKPeGrRZ:kcm4FmowdHoSphraHcpOaKHj

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • UPX dump on OEP (original entry point)

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks