General

  • Target

    78b10544e6d9080d6581f8e8379b8425d3924565fff1c9b8948b48fbe4813301

  • Size

    13.4MB

  • Sample

    240630-ng4dlazflp

  • MD5

    153d97bc44f00ade88c655961811f764

  • SHA1

    5028e44593857a72cad7c7181cc92083392533c8

  • SHA256

    78b10544e6d9080d6581f8e8379b8425d3924565fff1c9b8948b48fbe4813301

  • SHA512

    fe58aa145d95407d4cf566f3377b2fb35683a31f5a76e38aef04e1a605ebbeaa92b654aceefbe6adcb38e8621d9aa66166bdefdb3ed75353bd09bd1d3b3bb056

  • SSDEEP

    393216:K5J0h0UZkvOYJPCGSotdxLZsOivhy25i7XKiEJU0:K5ugRJPCpKvqOiM25iE

Malware Config

Targets

    • Target

      78b10544e6d9080d6581f8e8379b8425d3924565fff1c9b8948b48fbe4813301

    • Size

      13.4MB

    • MD5

      153d97bc44f00ade88c655961811f764

    • SHA1

      5028e44593857a72cad7c7181cc92083392533c8

    • SHA256

      78b10544e6d9080d6581f8e8379b8425d3924565fff1c9b8948b48fbe4813301

    • SHA512

      fe58aa145d95407d4cf566f3377b2fb35683a31f5a76e38aef04e1a605ebbeaa92b654aceefbe6adcb38e8621d9aa66166bdefdb3ed75353bd09bd1d3b3bb056

    • SSDEEP

      393216:K5J0h0UZkvOYJPCGSotdxLZsOivhy25i7XKiEJU0:K5ugRJPCpKvqOiM25iE

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • ACProtect 1.3x - 1.4x DLL software

      Detects file using ACProtect software.

    • Executes dropped EXE

    • Loads dropped DLL

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix ATT&CK v13

Tasks