General

  • Target

    4da5e179858b40208c36458051199609a721aa93e3973abd75ee5886661d09bd

  • Size

    61KB

  • Sample

    240630-z6khkawbmc

  • MD5

    a2b73faba4334ce019f71e22a1bd996f

  • SHA1

    b77fe53d99ad523cde4179aa6762f198236c3fef

  • SHA256

    4da5e179858b40208c36458051199609a721aa93e3973abd75ee5886661d09bd

  • SHA512

    255fcc877449ba46723151760dd1f29e2d3045bd8a2cf6f4adb10de0b77da80c4ab1c58395f348e58b7cecfea486b5e3437fc511a4a69205cfe0a57d07d27872

  • SSDEEP

    1536:9Q8hoOAesfYvcyjfS3H9yl8Q1pmdBcxedLxNDIvuzkzNb:ymb3NkkiQ3mdBjFIvlpb

Malware Config

Targets

    • Target

      4da5e179858b40208c36458051199609a721aa93e3973abd75ee5886661d09bd

    • Size

      61KB

    • MD5

      a2b73faba4334ce019f71e22a1bd996f

    • SHA1

      b77fe53d99ad523cde4179aa6762f198236c3fef

    • SHA256

      4da5e179858b40208c36458051199609a721aa93e3973abd75ee5886661d09bd

    • SHA512

      255fcc877449ba46723151760dd1f29e2d3045bd8a2cf6f4adb10de0b77da80c4ab1c58395f348e58b7cecfea486b5e3437fc511a4a69205cfe0a57d07d27872

    • SSDEEP

      1536:9Q8hoOAesfYvcyjfS3H9yl8Q1pmdBcxedLxNDIvuzkzNb:ymb3NkkiQ3mdBjFIvlpb

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • UPX dump on OEP (original entry point)

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks