General

  • Target

    37ba914492f25cfa6220f7648e8ee2acb62faf95607e02505d925db8589319a6

  • Size

    279KB

  • Sample

    240630-y79neavarc

  • MD5

    b0e99ca4af21bffa9eddc2f0f901e5f5

  • SHA1

    e66c2622202e12c291f044a004511a28ebbd31bc

  • SHA256

    37ba914492f25cfa6220f7648e8ee2acb62faf95607e02505d925db8589319a6

  • SHA512

    bfdf67dd226579d1e737ad25cee04d16b1d10e5bff2b4e970dbf6fa1f432af662943b90d34f0b93ae580c677e1c96f7db36fff510e020f29f7b67deefe78fe46

  • SSDEEP

    6144:n3C9BRIG0asYFm71m8+GdkB9yMu7VvemW7:n3C9uYA71kSMu4

Malware Config

Targets

    • Target

      37ba914492f25cfa6220f7648e8ee2acb62faf95607e02505d925db8589319a6

    • Size

      279KB

    • MD5

      b0e99ca4af21bffa9eddc2f0f901e5f5

    • SHA1

      e66c2622202e12c291f044a004511a28ebbd31bc

    • SHA256

      37ba914492f25cfa6220f7648e8ee2acb62faf95607e02505d925db8589319a6

    • SHA512

      bfdf67dd226579d1e737ad25cee04d16b1d10e5bff2b4e970dbf6fa1f432af662943b90d34f0b93ae580c677e1c96f7db36fff510e020f29f7b67deefe78fe46

    • SSDEEP

      6144:n3C9BRIG0asYFm71m8+GdkB9yMu7VvemW7:n3C9uYA71kSMu4

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • UPX dump on OEP (original entry point)

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks