General

  • Target

    11ac1adf89728f36646077658493a4b849fdfcf2e835c9bcee2cf5a5bd09adb1.exe

  • Size

    69KB

  • Sample

    240704-1wm2datdrd

  • MD5

    e1942e31219e8c0a590aabcce6520b20

  • SHA1

    3702c9272c08669d1c22f1c600fe062276a88794

  • SHA256

    11ac1adf89728f36646077658493a4b849fdfcf2e835c9bcee2cf5a5bd09adb1

  • SHA512

    a6a2d36ff714903cc4ecdf26c573a8f8458413f88d3ee1d783934462daeaffc7d9260e929c5432451823eac887a955aab583ef2792621f1e6bcfad2b5bc2b53e

  • SSDEEP

    1536:9Q8hoOAesfYvcyjfS3H9yl8Q1pmdBcxedLxND0yUPqrDZVTrT:ymb3NkkiQ3mdBjF0yUm7r

Malware Config

Targets

    • Target

      11ac1adf89728f36646077658493a4b849fdfcf2e835c9bcee2cf5a5bd09adb1.exe

    • Size

      69KB

    • MD5

      e1942e31219e8c0a590aabcce6520b20

    • SHA1

      3702c9272c08669d1c22f1c600fe062276a88794

    • SHA256

      11ac1adf89728f36646077658493a4b849fdfcf2e835c9bcee2cf5a5bd09adb1

    • SHA512

      a6a2d36ff714903cc4ecdf26c573a8f8458413f88d3ee1d783934462daeaffc7d9260e929c5432451823eac887a955aab583ef2792621f1e6bcfad2b5bc2b53e

    • SSDEEP

      1536:9Q8hoOAesfYvcyjfS3H9yl8Q1pmdBcxedLxND0yUPqrDZVTrT:ymb3NkkiQ3mdBjF0yUm7r

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks