General

  • Target

    ba7ff6682de900e07c6420974c5292fece15f469af4b19b2d3c90e06a7052d98

  • Size

    450KB

  • Sample

    240701-ccyrrssfmc

  • MD5

    c0be1ba073c5841e4b909dd677667910

  • SHA1

    61a324cbd418467b8be2eed93e0485af5d6acb22

  • SHA256

    ba7ff6682de900e07c6420974c5292fece15f469af4b19b2d3c90e06a7052d98

  • SHA512

    ca43cacb0603890f0b304fad82225c4e56cdb3aa5189815add8632af67a225c5ab721758095358c14659e6a40e77d1e4be06f3361c1446ddef2490042e726329

  • SSDEEP

    6144:8cm7ImGddXmNt251UriZFwfsDX2UznsaFVNJCMKAbex:q7Tc2NYHUrAwfMp3CDx

Malware Config

Targets

    • Target

      ba7ff6682de900e07c6420974c5292fece15f469af4b19b2d3c90e06a7052d98

    • Size

      450KB

    • MD5

      c0be1ba073c5841e4b909dd677667910

    • SHA1

      61a324cbd418467b8be2eed93e0485af5d6acb22

    • SHA256

      ba7ff6682de900e07c6420974c5292fece15f469af4b19b2d3c90e06a7052d98

    • SHA512

      ca43cacb0603890f0b304fad82225c4e56cdb3aa5189815add8632af67a225c5ab721758095358c14659e6a40e77d1e4be06f3361c1446ddef2490042e726329

    • SSDEEP

      6144:8cm7ImGddXmNt251UriZFwfsDX2UznsaFVNJCMKAbex:q7Tc2NYHUrAwfMp3CDx

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • UPX dump on OEP (original entry point)

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks