General

  • Target

    1b1898c9325068726246f127417a8790e8d56bd230949a4eb028831e33f3f1af

  • Size

    288KB

  • Sample

    240630-xz2gdswern

  • MD5

    c8298be3b8db3beb5c4d5547cb0ba17e

  • SHA1

    5a19ed647c7705e07fa508e2c56130b492881862

  • SHA256

    1b1898c9325068726246f127417a8790e8d56bd230949a4eb028831e33f3f1af

  • SHA512

    a2ec463f56bbb38a42326fcc971ce70bf5d1f508a9aaf1ffb0f171e9571e00379e793ec38388eae608c61b5d2ccf7eeb6d6fe884959812dbfa4d00a78a5c1be2

  • SSDEEP

    3072:ThOm2sI93UufdC67cipfmCiiiXAQ5lpBoGYwNNhu0CzhKPJFt:Tcm7ImGddXlWrXF5lpKGYV0wh6Jr

Malware Config

Targets

    • Target

      1b1898c9325068726246f127417a8790e8d56bd230949a4eb028831e33f3f1af

    • Size

      288KB

    • MD5

      c8298be3b8db3beb5c4d5547cb0ba17e

    • SHA1

      5a19ed647c7705e07fa508e2c56130b492881862

    • SHA256

      1b1898c9325068726246f127417a8790e8d56bd230949a4eb028831e33f3f1af

    • SHA512

      a2ec463f56bbb38a42326fcc971ce70bf5d1f508a9aaf1ffb0f171e9571e00379e793ec38388eae608c61b5d2ccf7eeb6d6fe884959812dbfa4d00a78a5c1be2

    • SSDEEP

      3072:ThOm2sI93UufdC67cipfmCiiiXAQ5lpBoGYwNNhu0CzhKPJFt:Tcm7ImGddXlWrXF5lpKGYV0wh6Jr

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • UPX dump on OEP (original entry point)

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks