General

  • Target

    c2bc1b4a4c45756ae437ed48cd5e4b2433cf75e9f0fd65723c5412993f537aa4

  • Size

    261KB

  • Sample

    240701-csqq4awgnm

  • MD5

    ec62e95ad56fcdbe2c080fd22f3d53eb

  • SHA1

    8cd16f45e30c6e421b8fb943a05e9ae2e105d203

  • SHA256

    c2bc1b4a4c45756ae437ed48cd5e4b2433cf75e9f0fd65723c5412993f537aa4

  • SHA512

    5ae90ba55fdd7afdb0a308afb51358aa0f71ccb2fa16bf1fbb72eef586f5280eed34b4892f982f0261ea8d06a6b3caf04f71d0b00b1a89c9a9ff7888c1fa16b8

  • SSDEEP

    6144:n3C9BRo7tvnJ9Fywhk/T4i37K3BoKg0qQ:n3C9ytvn8whkb4i3e3GF/Q

Malware Config

Targets

    • Target

      c2bc1b4a4c45756ae437ed48cd5e4b2433cf75e9f0fd65723c5412993f537aa4

    • Size

      261KB

    • MD5

      ec62e95ad56fcdbe2c080fd22f3d53eb

    • SHA1

      8cd16f45e30c6e421b8fb943a05e9ae2e105d203

    • SHA256

      c2bc1b4a4c45756ae437ed48cd5e4b2433cf75e9f0fd65723c5412993f537aa4

    • SHA512

      5ae90ba55fdd7afdb0a308afb51358aa0f71ccb2fa16bf1fbb72eef586f5280eed34b4892f982f0261ea8d06a6b3caf04f71d0b00b1a89c9a9ff7888c1fa16b8

    • SSDEEP

      6144:n3C9BRo7tvnJ9Fywhk/T4i37K3BoKg0qQ:n3C9ytvn8whkb4i3e3GF/Q

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • UPX dump on OEP (original entry point)

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks