General

  • Target

    13b6ebb93029b7f7c4bb6848d0f78eed2f7252f321b77a736cfbff81cc16ae4e

  • Size

    208KB

  • Sample

    240630-xl3sassfmb

  • MD5

    05ad4047e3a7c1e89221a9d09a40fd09

  • SHA1

    682421591c8acfae6cd9a6f95f6358a2d695451d

  • SHA256

    13b6ebb93029b7f7c4bb6848d0f78eed2f7252f321b77a736cfbff81cc16ae4e

  • SHA512

    e866385fe4a7ed8f969473c1e31868ca1951cbab714dc83b92101f38abfb2c5256964258ce50056ad440309aab9858c71f1883aed1c1ed52566a78089e733461

  • SSDEEP

    3072:ymb3NkkiQ3mdBjFo73PYP1lri3KoSV31L:n3C9BRo7MlrWKo+lL

Malware Config

Targets

    • Target

      13b6ebb93029b7f7c4bb6848d0f78eed2f7252f321b77a736cfbff81cc16ae4e

    • Size

      208KB

    • MD5

      05ad4047e3a7c1e89221a9d09a40fd09

    • SHA1

      682421591c8acfae6cd9a6f95f6358a2d695451d

    • SHA256

      13b6ebb93029b7f7c4bb6848d0f78eed2f7252f321b77a736cfbff81cc16ae4e

    • SHA512

      e866385fe4a7ed8f969473c1e31868ca1951cbab714dc83b92101f38abfb2c5256964258ce50056ad440309aab9858c71f1883aed1c1ed52566a78089e733461

    • SSDEEP

      3072:ymb3NkkiQ3mdBjFo73PYP1lri3KoSV31L:n3C9BRo7MlrWKo+lL

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • UPX dump on OEP (original entry point)

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks