General

  • Target

    e605a840e9062aa8ec172917fe66a1000d44301e8f973793cd3070e16a4f01ae

  • Size

    182KB

  • Sample

    240701-ehbkjavhqb

  • MD5

    155a905fc8fe8762b335e24c0d61dd23

  • SHA1

    6502533920875ac598b1f675c9515fe7ee1a4c2f

  • SHA256

    e605a840e9062aa8ec172917fe66a1000d44301e8f973793cd3070e16a4f01ae

  • SHA512

    36847ee2c05f6e868be51e033c7704f0709890f1a852a3b731a2c061218e0264429967dbe39ad0bc43541565df5692c244c58a24112047c57c2f0f224e593737

  • SSDEEP

    1536:PvQBeOGtrYSSsrc93UBIfdC67m6AJiqgT4+IJPhbMZ:PhOm2sI93UufdC67ciJTm5hIZ

Malware Config

Targets

    • Target

      e605a840e9062aa8ec172917fe66a1000d44301e8f973793cd3070e16a4f01ae

    • Size

      182KB

    • MD5

      155a905fc8fe8762b335e24c0d61dd23

    • SHA1

      6502533920875ac598b1f675c9515fe7ee1a4c2f

    • SHA256

      e605a840e9062aa8ec172917fe66a1000d44301e8f973793cd3070e16a4f01ae

    • SHA512

      36847ee2c05f6e868be51e033c7704f0709890f1a852a3b731a2c061218e0264429967dbe39ad0bc43541565df5692c244c58a24112047c57c2f0f224e593737

    • SSDEEP

      1536:PvQBeOGtrYSSsrc93UBIfdC67m6AJiqgT4+IJPhbMZ:PhOm2sI93UufdC67ciJTm5hIZ

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • UPX dump on OEP (original entry point)

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks