General

  • Target

    a9eb7cba84ab4c0aeceedb7886ccda1041ead0bd39fe3215c2830d12c83094dc

  • Size

    185KB

  • Sample

    240701-bkqwfs1gnb

  • MD5

    6375ba3cac7ddae754678c391448b2a4

  • SHA1

    a54e29a955ca2a5a29a6a458d61c4c33e0334b0d

  • SHA256

    a9eb7cba84ab4c0aeceedb7886ccda1041ead0bd39fe3215c2830d12c83094dc

  • SHA512

    c3e43cd85cc4ef8223e1bd50cbf793b2883d63ec81c6f982c42a14f8b157652e020953e7b26d448a5b2a1afb4f6e359517923890c916473f82b912edb105219e

  • SSDEEP

    3072:chOmTsF93UYfwC6GIout5pi8rY9AABa1U+a88Xu3VodyikZfhnJtJI+i:ccm4FmowdHoS5ddWX+afdlkpPtJIv

Malware Config

Targets

    • Target

      a9eb7cba84ab4c0aeceedb7886ccda1041ead0bd39fe3215c2830d12c83094dc

    • Size

      185KB

    • MD5

      6375ba3cac7ddae754678c391448b2a4

    • SHA1

      a54e29a955ca2a5a29a6a458d61c4c33e0334b0d

    • SHA256

      a9eb7cba84ab4c0aeceedb7886ccda1041ead0bd39fe3215c2830d12c83094dc

    • SHA512

      c3e43cd85cc4ef8223e1bd50cbf793b2883d63ec81c6f982c42a14f8b157652e020953e7b26d448a5b2a1afb4f6e359517923890c916473f82b912edb105219e

    • SSDEEP

      3072:chOmTsF93UYfwC6GIout5pi8rY9AABa1U+a88Xu3VodyikZfhnJtJI+i:ccm4FmowdHoS5ddWX+afdlkpPtJIv

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • UPX dump on OEP (original entry point)

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks