General

  • Target

    5fb38305463082f0b38ba1722afd8e1f6df8b2ac492e443453235a09f1c9feca

  • Size

    451KB

  • Sample

    240704-13advsthld

  • MD5

    b8be22692e46cbe9a9def4e3d9ee1e3a

  • SHA1

    694f54404d285275a1557899e05133d33e8d0e70

  • SHA256

    5fb38305463082f0b38ba1722afd8e1f6df8b2ac492e443453235a09f1c9feca

  • SHA512

    d74f824fc9a645ec08586d9c7cac9f7b077a278da4ff41f0e3004dcdb1d12f9856fd8508da8f2d3760b4bb59f64018e0dba908f0840755f6b626d2f123e105cb

  • SSDEEP

    6144:8cm7ImGddXmNt251UriZFwfsDX2UznsaFVNJCMKAbeA:q7Tc2NYHUrAwfMp3CDA

Malware Config

Targets

    • Target

      5fb38305463082f0b38ba1722afd8e1f6df8b2ac492e443453235a09f1c9feca

    • Size

      451KB

    • MD5

      b8be22692e46cbe9a9def4e3d9ee1e3a

    • SHA1

      694f54404d285275a1557899e05133d33e8d0e70

    • SHA256

      5fb38305463082f0b38ba1722afd8e1f6df8b2ac492e443453235a09f1c9feca

    • SHA512

      d74f824fc9a645ec08586d9c7cac9f7b077a278da4ff41f0e3004dcdb1d12f9856fd8508da8f2d3760b4bb59f64018e0dba908f0840755f6b626d2f123e105cb

    • SSDEEP

      6144:8cm7ImGddXmNt251UriZFwfsDX2UznsaFVNJCMKAbeA:q7Tc2NYHUrAwfMp3CDA

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks