General

  • Target

    5c12a32683a27240a180a2614fc00c883d35901e138764f127342e6beb36801e

  • Size

    13.3MB

  • Sample

    240701-rrrdkawfld

  • MD5

    0809ebfe13eb72817da8d6a7ec3fe7c2

  • SHA1

    3ccdecfb45070ee78f2ae67aeb59d7f9bde2fed0

  • SHA256

    5c12a32683a27240a180a2614fc00c883d35901e138764f127342e6beb36801e

  • SHA512

    487e27d3915aba5d85067700a3c773847221e3f1a8e7e7b22b635d73d460e9ea8f2d3dd4fae6a134fc4345052c0f44575f9a1bfc56c593bf9387916b2fc652d6

  • SSDEEP

    393216:hlHlMGl5ARb05g3FO2hdIcHB0GuW7yi1SrZ:htSrEaFOQBbz91S

Malware Config

Targets

    • Target

      5c12a32683a27240a180a2614fc00c883d35901e138764f127342e6beb36801e

    • Size

      13.3MB

    • MD5

      0809ebfe13eb72817da8d6a7ec3fe7c2

    • SHA1

      3ccdecfb45070ee78f2ae67aeb59d7f9bde2fed0

    • SHA256

      5c12a32683a27240a180a2614fc00c883d35901e138764f127342e6beb36801e

    • SHA512

      487e27d3915aba5d85067700a3c773847221e3f1a8e7e7b22b635d73d460e9ea8f2d3dd4fae6a134fc4345052c0f44575f9a1bfc56c593bf9387916b2fc652d6

    • SSDEEP

      393216:hlHlMGl5ARb05g3FO2hdIcHB0GuW7yi1SrZ:htSrEaFOQBbz91S

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • ACProtect 1.3x - 1.4x DLL software

      Detects file using ACProtect software.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks