General

  • Target

    f94705e6cf9c76b7491a3bee3a3d12fc5c7f7b8054b75a319c75a2a0921be878

  • Size

    12.1MB

  • Sample

    240701-rpz8pazdqp

  • MD5

    4326785c2075efdf528d7665fac35226

  • SHA1

    83fb1557e6c6f3ee6f121e0615822c15043a1c07

  • SHA256

    f94705e6cf9c76b7491a3bee3a3d12fc5c7f7b8054b75a319c75a2a0921be878

  • SHA512

    d892a95527b927e21a3f86da77fbb8dc33a5120314c89a334351eb92da150898d109528a42c84d6471bb8bb8451a4b65cad29c67490f72e5f45844ed00800b2d

  • SSDEEP

    393216:UemA69ksYbw3hL2+jbAXYKRqy043Ozk7:UevnsYbiV2QAVKk

Malware Config

Targets

    • Target

      f94705e6cf9c76b7491a3bee3a3d12fc5c7f7b8054b75a319c75a2a0921be878

    • Size

      12.1MB

    • MD5

      4326785c2075efdf528d7665fac35226

    • SHA1

      83fb1557e6c6f3ee6f121e0615822c15043a1c07

    • SHA256

      f94705e6cf9c76b7491a3bee3a3d12fc5c7f7b8054b75a319c75a2a0921be878

    • SHA512

      d892a95527b927e21a3f86da77fbb8dc33a5120314c89a334351eb92da150898d109528a42c84d6471bb8bb8451a4b65cad29c67490f72e5f45844ed00800b2d

    • SSDEEP

      393216:UemA69ksYbw3hL2+jbAXYKRqy043Ozk7:UevnsYbiV2QAVKk

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • ACProtect 1.3x - 1.4x DLL software

      Detects file using ACProtect software.

    • Loads dropped DLL

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks