General

  • Target

    fabc8a303bf5f6c919d71f955c960cf6e81ed74cce78ed8d5bcf212d37cdcb23

  • Size

    13.6MB

  • Sample

    240701-e39ytszbnk

  • MD5

    d370b99f64875fa4cc7b741a94d92502

  • SHA1

    4797e5d81ae10fb93bc889aeba63ae80b5acc5c6

  • SHA256

    fabc8a303bf5f6c919d71f955c960cf6e81ed74cce78ed8d5bcf212d37cdcb23

  • SHA512

    bf1a90dadaa10780cd8184f1135d82766b6dbdb0f6d00cda7f62fdfb1b488a42c26e496a75d7e6374c3b0f7a45897ca8b0e107789c32b45d72566782a6e9bf1d

  • SSDEEP

    393216:MAn5edM99vf0zJpuVbL+xB+f165qeQVCc5v:L5sM9q7uJ+xBm8qvtp

Malware Config

Targets

    • Target

      fabc8a303bf5f6c919d71f955c960cf6e81ed74cce78ed8d5bcf212d37cdcb23

    • Size

      13.6MB

    • MD5

      d370b99f64875fa4cc7b741a94d92502

    • SHA1

      4797e5d81ae10fb93bc889aeba63ae80b5acc5c6

    • SHA256

      fabc8a303bf5f6c919d71f955c960cf6e81ed74cce78ed8d5bcf212d37cdcb23

    • SHA512

      bf1a90dadaa10780cd8184f1135d82766b6dbdb0f6d00cda7f62fdfb1b488a42c26e496a75d7e6374c3b0f7a45897ca8b0e107789c32b45d72566782a6e9bf1d

    • SSDEEP

      393216:MAn5edM99vf0zJpuVbL+xB+f165qeQVCc5v:L5sM9q7uJ+xBm8qvtp

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • ACProtect 1.3x - 1.4x DLL software

      Detects file using ACProtect software.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks