General

  • Target

    d5bc34aed7e098d7a2a2f6f6039b374a3a3a4013a58f1dc7825f7e1889dff49b

  • Size

    587KB

  • Sample

    240705-dxfmcstfjg

  • MD5

    baf25f44086a6265c7ea4f718c33b943

  • SHA1

    04192ed4a19df983a8efd4bbb20b050ceee9be6a

  • SHA256

    d5bc34aed7e098d7a2a2f6f6039b374a3a3a4013a58f1dc7825f7e1889dff49b

  • SHA512

    6f20ab8c87565511a6c0f1f9cf27933ec9f589b88a4d78756d2989c3c2fee37d644870d1fa64e0f85347e8a348d3454ce9f6b292f07774894f5d27c78b487ea6

  • SSDEEP

    12288:n3C9ytvngQjuPh2kkkkK4kXkkkkkkkkl888888888888888888nusMH0QiZL:SgdnJKPh2kkkkK4kXkkkkkkkkJL

Malware Config

Targets

    • Target

      d5bc34aed7e098d7a2a2f6f6039b374a3a3a4013a58f1dc7825f7e1889dff49b

    • Size

      587KB

    • MD5

      baf25f44086a6265c7ea4f718c33b943

    • SHA1

      04192ed4a19df983a8efd4bbb20b050ceee9be6a

    • SHA256

      d5bc34aed7e098d7a2a2f6f6039b374a3a3a4013a58f1dc7825f7e1889dff49b

    • SHA512

      6f20ab8c87565511a6c0f1f9cf27933ec9f589b88a4d78756d2989c3c2fee37d644870d1fa64e0f85347e8a348d3454ce9f6b292f07774894f5d27c78b487ea6

    • SSDEEP

      12288:n3C9ytvngQjuPh2kkkkK4kXkkkkkkkkl888888888888888888nusMH0QiZL:SgdnJKPh2kkkkK4kXkkkkkkkkJL

    • Blackmoon, KrBanker

      Blackmoon also known as KrBanker is banking trojan first discovered in early 2014.

    • Detect Blackmoon payload

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks