General

  • Target

    406aa985efb3a630109d6274a4f64f957988ad874e2d816af0405e31a05c27af

  • Size

    158KB

  • Sample

    240630-zmqv8svfjg

  • MD5

    fe4afb4103b3bcb481ada6ea0ce5bd08

  • SHA1

    028e2d6929de4db61b7cf3b66eac283e23b76c94

  • SHA256

    406aa985efb3a630109d6274a4f64f957988ad874e2d816af0405e31a05c27af

  • SHA512

    492e98be0c46f52e0977c31e7fd191cf63ef05f201ef0abcc9f187f4ef977e9a66f1abcda333478c8826b9768a306f8fbd73ca014c021ceeeee147d6ce946056

  • SSDEEP

    3072:khOmTsF93UYfwC6GIoutpYcvrqrE66kropO6BWlPFH4oGPwJwJE21rn:kcm4FmowdHoSphraHcpOFltH4oGPjJEY

Malware Config

Targets

    • Target

      406aa985efb3a630109d6274a4f64f957988ad874e2d816af0405e31a05c27af

    • Size

      158KB

    • MD5

      fe4afb4103b3bcb481ada6ea0ce5bd08

    • SHA1

      028e2d6929de4db61b7cf3b66eac283e23b76c94

    • SHA256

      406aa985efb3a630109d6274a4f64f957988ad874e2d816af0405e31a05c27af

    • SHA512

      492e98be0c46f52e0977c31e7fd191cf63ef05f201ef0abcc9f187f4ef977e9a66f1abcda333478c8826b9768a306f8fbd73ca014c021ceeeee147d6ce946056

    • SSDEEP

      3072:khOmTsF93UYfwC6GIoutpYcvrqrE66kropO6BWlPFH4oGPwJwJE21rn:kcm4FmowdHoSphraHcpOFltH4oGPjJEY

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • UPX dump on OEP (original entry point)

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks