General

  • Target

    1a57fa5f809d18755ed137f911ea8ecc2bd07d678f5bace0c256195829284e45.exe

  • Size

    107KB

  • Sample

    240704-3f7rysvhrn

  • MD5

    4e4270bb3b5714b2fd5e418e44a180c0

  • SHA1

    6ad6bcfdeda14abfaf4e1ca86ad1e5454e5a0181

  • SHA256

    1a57fa5f809d18755ed137f911ea8ecc2bd07d678f5bace0c256195829284e45

  • SHA512

    2aec4addbe6b4425f24be1bd6cb5934e6d35f01d986fb678e6f1eb432e51a453f6f20a87a215979441149e2e7f64abad56919d20aae23198a59befa05922a1b6

  • SSDEEP

    1536:9Q8hoOAesfYvcyjfS3H9yl8Q1pmdBcxedLxNDoTNKDeS98hPUdHV7RNzfJN7pFL:ymb3NkkiQ3mdBjFo5KDe88g1fD7jL

Malware Config

Targets

    • Target

      1a57fa5f809d18755ed137f911ea8ecc2bd07d678f5bace0c256195829284e45.exe

    • Size

      107KB

    • MD5

      4e4270bb3b5714b2fd5e418e44a180c0

    • SHA1

      6ad6bcfdeda14abfaf4e1ca86ad1e5454e5a0181

    • SHA256

      1a57fa5f809d18755ed137f911ea8ecc2bd07d678f5bace0c256195829284e45

    • SHA512

      2aec4addbe6b4425f24be1bd6cb5934e6d35f01d986fb678e6f1eb432e51a453f6f20a87a215979441149e2e7f64abad56919d20aae23198a59befa05922a1b6

    • SSDEEP

      1536:9Q8hoOAesfYvcyjfS3H9yl8Q1pmdBcxedLxNDoTNKDeS98hPUdHV7RNzfJN7pFL:ymb3NkkiQ3mdBjFo5KDe88g1fD7jL

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks