General

  • Target

    460fd22e825972536bee86f8354477dd34e7e51ebac18b633a2d0f3b94b7d62e

  • Size

    69KB

  • Sample

    240704-z25ypsyhnl

  • MD5

    831976b91c46b871ea7dc408ee8de1b8

  • SHA1

    7821e3e01b720c4cf0b4d847abdb30cc75b709e8

  • SHA256

    460fd22e825972536bee86f8354477dd34e7e51ebac18b633a2d0f3b94b7d62e

  • SHA512

    fbe28a1a0549aef1119660d681c3dcc9e31ccf5d07a49163e4bb919ebb66f22b3a262b1454454ef2c4596ecbf5a541c27b2bcd7398522b7d4e62a34194166d03

  • SSDEEP

    1536:9Q8hoOAesfYvcyjfS3H9yl8Q1pmdBcxedLxND0yUPqrDZVTr7:ymb3NkkiQ3mdBjF0yUm7T

Malware Config

Targets

    • Target

      460fd22e825972536bee86f8354477dd34e7e51ebac18b633a2d0f3b94b7d62e

    • Size

      69KB

    • MD5

      831976b91c46b871ea7dc408ee8de1b8

    • SHA1

      7821e3e01b720c4cf0b4d847abdb30cc75b709e8

    • SHA256

      460fd22e825972536bee86f8354477dd34e7e51ebac18b633a2d0f3b94b7d62e

    • SHA512

      fbe28a1a0549aef1119660d681c3dcc9e31ccf5d07a49163e4bb919ebb66f22b3a262b1454454ef2c4596ecbf5a541c27b2bcd7398522b7d4e62a34194166d03

    • SSDEEP

      1536:9Q8hoOAesfYvcyjfS3H9yl8Q1pmdBcxedLxND0yUPqrDZVTr7:ymb3NkkiQ3mdBjF0yUm7T

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks