General

  • Target

    9de86d6bd0da9db94bf9811578abc9cae528ede4a080052e466d53a32674af83

  • Size

    228KB

  • Sample

    240701-a13phs1blc

  • MD5

    f7f99f4c0b59de345267246008d4afc1

  • SHA1

    33dd9ab34f026c1ba58dd85b84ac1558846d5132

  • SHA256

    9de86d6bd0da9db94bf9811578abc9cae528ede4a080052e466d53a32674af83

  • SHA512

    f898830e571c410922deb65c222e09dd8cafba0960f761b66fc264479a913fc83c904ff4ea142d88e72b90fcc98f91ffefb4c8c0b14cf40e5ff11993b4bbae38

  • SSDEEP

    6144:Jcm4FmowdHoS3dGmS4Z1hraHcpOaKHpaztyzl+Sj:T4wFHoS3dJS4ZzeFaKHpCcz

Malware Config

Targets

    • Target

      9de86d6bd0da9db94bf9811578abc9cae528ede4a080052e466d53a32674af83

    • Size

      228KB

    • MD5

      f7f99f4c0b59de345267246008d4afc1

    • SHA1

      33dd9ab34f026c1ba58dd85b84ac1558846d5132

    • SHA256

      9de86d6bd0da9db94bf9811578abc9cae528ede4a080052e466d53a32674af83

    • SHA512

      f898830e571c410922deb65c222e09dd8cafba0960f761b66fc264479a913fc83c904ff4ea142d88e72b90fcc98f91ffefb4c8c0b14cf40e5ff11993b4bbae38

    • SSDEEP

      6144:Jcm4FmowdHoS3dGmS4Z1hraHcpOaKHpaztyzl+Sj:T4wFHoS3dJS4ZzeFaKHpCcz

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • UPX dump on OEP (original entry point)

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks