General

  • Target

    0d281d37a2b06a28e05f77b2e155156c8de93297f20cc7522f32e696d493464e.exe

  • Size

    100KB

  • Sample

    240704-z3jf4ayhpp

  • MD5

    11394a369f7286bacf1c26de3c8cdbb0

  • SHA1

    43eaf8f4ef1e9424c8b1948cab93b1e3855bdcbc

  • SHA256

    0d281d37a2b06a28e05f77b2e155156c8de93297f20cc7522f32e696d493464e

  • SHA512

    a12e7714595f47a8952c4ff222318d102397285145e94379987f601d1312c77bc70f3fbc0b9fd6673bda6d85514a18f0c72a12f69c11ab168577e43670d1af45

  • SSDEEP

    1536:9Q8hoOAesfYvcyjfS3H9yl8Q1pmdBcxedLxNDodtzn6zDaE0R5C:ymb3NkkiQ3mdBjFodt2zE3C

Malware Config

Targets

    • Target

      0d281d37a2b06a28e05f77b2e155156c8de93297f20cc7522f32e696d493464e.exe

    • Size

      100KB

    • MD5

      11394a369f7286bacf1c26de3c8cdbb0

    • SHA1

      43eaf8f4ef1e9424c8b1948cab93b1e3855bdcbc

    • SHA256

      0d281d37a2b06a28e05f77b2e155156c8de93297f20cc7522f32e696d493464e

    • SHA512

      a12e7714595f47a8952c4ff222318d102397285145e94379987f601d1312c77bc70f3fbc0b9fd6673bda6d85514a18f0c72a12f69c11ab168577e43670d1af45

    • SSDEEP

      1536:9Q8hoOAesfYvcyjfS3H9yl8Q1pmdBcxedLxNDodtzn6zDaE0R5C:ymb3NkkiQ3mdBjFodt2zE3C

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks