General

  • Target

    f736f8eef1cb29c360f77b181182f2b4dd0f2af2826b19ebb65ea100af66221a

  • Size

    10.6MB

  • Sample

    240630-synrpazekf

  • MD5

    35bfeff634963ed20a003eec45e21d7e

  • SHA1

    d4a5d090b05a0643cc8f01581939f98ba6587fa3

  • SHA256

    f736f8eef1cb29c360f77b181182f2b4dd0f2af2826b19ebb65ea100af66221a

  • SHA512

    ad5bead049e4e518798cddd76cce0d17aeac818dfd1ad71d6da37da112f1d3de51bd7eef2f5af536d63f1734d5ef39755f8658afad0d61e08a47ab4d3447d417

  • SSDEEP

    196608:10/mS2KWUGNEoiN/A4sLhg6jr7fNVIpiNYUpbimDV591R/ioEe3qorBOMSh:iOupGNvLC6jrZVIQNYiumJ/vJaoyh

Score
10/10

Malware Config

Targets

    • Target

      f736f8eef1cb29c360f77b181182f2b4dd0f2af2826b19ebb65ea100af66221a

    • Size

      10.6MB

    • MD5

      35bfeff634963ed20a003eec45e21d7e

    • SHA1

      d4a5d090b05a0643cc8f01581939f98ba6587fa3

    • SHA256

      f736f8eef1cb29c360f77b181182f2b4dd0f2af2826b19ebb65ea100af66221a

    • SHA512

      ad5bead049e4e518798cddd76cce0d17aeac818dfd1ad71d6da37da112f1d3de51bd7eef2f5af536d63f1734d5ef39755f8658afad0d61e08a47ab4d3447d417

    • SSDEEP

      196608:10/mS2KWUGNEoiN/A4sLhg6jr7fNVIpiNYUpbimDV591R/ioEe3qorBOMSh:iOupGNvLC6jrZVIQNYiumJ/vJaoyh

    Score
    10/10
    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • Enumerates connected drives

      Attempts to read the root path of hard drives other than the default C: drive.

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

Peripheral Device Discovery

1
T1120

System Information Discovery

1
T1082

Tasks