General

  • Target

    22400d8cf569b1e56891b464c39cd52c35e10ec3cafd031f303960c0d324825c.exe

  • Size

    842KB

  • Sample

    240705-a13phsyamj

  • MD5

    cec61c10915c15976c60cf62cad60820

  • SHA1

    bf8a250e6030cac8d47875db1c612f32218ccaf7

  • SHA256

    22400d8cf569b1e56891b464c39cd52c35e10ec3cafd031f303960c0d324825c

  • SHA512

    1c1bba78fe6dd0b0310209e86cadf0a16945ac4658bccb3217732dcac88a69d583837f2aeab6e738737e4149dd0cba899aaa9e735fbd45db0199a5d337e6e7c8

  • SSDEEP

    24576:Sgdn8whSenedn8whhdn76gdn8whSfgdn8whSzj:TFyVPfk

Malware Config

Targets

    • Target

      22400d8cf569b1e56891b464c39cd52c35e10ec3cafd031f303960c0d324825c.exe

    • Size

      842KB

    • MD5

      cec61c10915c15976c60cf62cad60820

    • SHA1

      bf8a250e6030cac8d47875db1c612f32218ccaf7

    • SHA256

      22400d8cf569b1e56891b464c39cd52c35e10ec3cafd031f303960c0d324825c

    • SHA512

      1c1bba78fe6dd0b0310209e86cadf0a16945ac4658bccb3217732dcac88a69d583837f2aeab6e738737e4149dd0cba899aaa9e735fbd45db0199a5d337e6e7c8

    • SSDEEP

      24576:Sgdn8whSenedn8whhdn76gdn8whSfgdn8whSzj:TFyVPfk

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks