General

  • Target

    9d11de54dac4699ca756d7fe865bed2f2361a0ea7f404e19898da2f7c9b41906

  • Size

    651KB

  • Sample

    240630-hq2y8sxgrp

  • MD5

    0ef4fecb574ae751d060617c7c189afb

  • SHA1

    0e67b5f72b1b3b498fbc6c5adf3a09db12c260d5

  • SHA256

    9d11de54dac4699ca756d7fe865bed2f2361a0ea7f404e19898da2f7c9b41906

  • SHA512

    6bc1b73eab51cabc74948738b77b409e1f5434f6316cbcea8be089ed826f85b7e48fefb76b7e655bdb42786a234389e946deb78f7f8b588efa85a4ab42e53101

  • SSDEEP

    12288:mptTCYQXWGgvjoLnJvSRdsZviQgdUMqWUOcEDHAAe3DuIBo0Xb6BznhoS1:m8X0jomsoQgVqWUOrgTafz5

Malware Config

Targets

    • Target

      9d11de54dac4699ca756d7fe865bed2f2361a0ea7f404e19898da2f7c9b41906

    • Size

      651KB

    • MD5

      0ef4fecb574ae751d060617c7c189afb

    • SHA1

      0e67b5f72b1b3b498fbc6c5adf3a09db12c260d5

    • SHA256

      9d11de54dac4699ca756d7fe865bed2f2361a0ea7f404e19898da2f7c9b41906

    • SHA512

      6bc1b73eab51cabc74948738b77b409e1f5434f6316cbcea8be089ed826f85b7e48fefb76b7e655bdb42786a234389e946deb78f7f8b588efa85a4ab42e53101

    • SSDEEP

      12288:mptTCYQXWGgvjoLnJvSRdsZviQgdUMqWUOcEDHAAe3DuIBo0Xb6BznhoS1:m8X0jomsoQgVqWUOrgTafz5

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • Downloads MZ/PE file

    • Drops file in Drivers directory

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks