General

  • Target

    5f4b736ac02f1b23bf1d960698955ce0a32a156fede40644d74f1042adfbb3a1

  • Size

    13.6MB

  • Sample

    240630-qmr9maycke

  • MD5

    eb5c4aa1891c0358fa2b94f3aa8d35d9

  • SHA1

    39ce8eb6c8accfa79bbe928c2142523a30e0ca50

  • SHA256

    5f4b736ac02f1b23bf1d960698955ce0a32a156fede40644d74f1042adfbb3a1

  • SHA512

    4ad60a725f34c4f6cfbb632e7128e0b9c7340d88c85358fe02e4566a9221dc63824d93d686b3826111fe69cb0b9486092f8d67a4e872098602f41a9ba9aed2a9

  • SSDEEP

    196608:o5w7vAwXCBpMX40lYq8E9Pi3Yl72d0x6Wuddob0Y4o6bfUTLV85Nyh0ladhP6c4U:5PJPi3v66Wwdo9aDUTLx1jL3w

Malware Config

Targets

    • Target

      5f4b736ac02f1b23bf1d960698955ce0a32a156fede40644d74f1042adfbb3a1

    • Size

      13.6MB

    • MD5

      eb5c4aa1891c0358fa2b94f3aa8d35d9

    • SHA1

      39ce8eb6c8accfa79bbe928c2142523a30e0ca50

    • SHA256

      5f4b736ac02f1b23bf1d960698955ce0a32a156fede40644d74f1042adfbb3a1

    • SHA512

      4ad60a725f34c4f6cfbb632e7128e0b9c7340d88c85358fe02e4566a9221dc63824d93d686b3826111fe69cb0b9486092f8d67a4e872098602f41a9ba9aed2a9

    • SSDEEP

      196608:o5w7vAwXCBpMX40lYq8E9Pi3Yl72d0x6Wuddob0Y4o6bfUTLV85Nyh0ladhP6c4U:5PJPi3v66Wwdo9aDUTLx1jL3w

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • ACProtect 1.3x - 1.4x DLL software

      Detects file using ACProtect software.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks