General

  • Target

    9e231f0def9dedf51cf37107bd2db9039cdcc423eaca7ba0d254adff738ef163

  • Size

    214KB

  • Sample

    240705-a85tva1arf

  • MD5

    b143dfef0404a9aee614c017349b5afd

  • SHA1

    863ab08ab14e84cbcd9e22c4c67ed5a59df09970

  • SHA256

    9e231f0def9dedf51cf37107bd2db9039cdcc423eaca7ba0d254adff738ef163

  • SHA512

    174178da2ff5d00d3c51e07fc71644108909c8abbc36a3f86fd1ff653067a2eef727a4861de28e31e66e084115b4b7361793c956d83e5acae85120b5434631f8

  • SSDEEP

    6144:Hcm4FmowdHoSrXZf8l/ubPzYNLPf4t+lT:V4wFHoSBK/ubLcfd

Malware Config

Targets

    • Target

      9e231f0def9dedf51cf37107bd2db9039cdcc423eaca7ba0d254adff738ef163

    • Size

      214KB

    • MD5

      b143dfef0404a9aee614c017349b5afd

    • SHA1

      863ab08ab14e84cbcd9e22c4c67ed5a59df09970

    • SHA256

      9e231f0def9dedf51cf37107bd2db9039cdcc423eaca7ba0d254adff738ef163

    • SHA512

      174178da2ff5d00d3c51e07fc71644108909c8abbc36a3f86fd1ff653067a2eef727a4861de28e31e66e084115b4b7361793c956d83e5acae85120b5434631f8

    • SSDEEP

      6144:Hcm4FmowdHoSrXZf8l/ubPzYNLPf4t+lT:V4wFHoSBK/ubLcfd

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks