🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 145af39418607f9a21c35aaa855b65e8019c4d35750cb70d515f9807b43a3f21. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Blackmoon


Vendor detections: 12


Intelligence 12 IOCs YARA 13 File information Comments

SHA256 hash: 145af39418607f9a21c35aaa855b65e8019c4d35750cb70d515f9807b43a3f21
SHA3-384 hash: 1edeccebdd8066808a5beb2618cbaa0f18cb5b592dec590c7c718b7b5656212d9b5763610ae323992a0d89006f27ad49
SHA1 hash: 5043b80e44a14c704abbabe58c3c405c255c6a87
MD5 hash: b4b622dd6692b0185bd1a284ac849d2f
humanhash: purple-failed-chicken-alabama
File name:允许注销@121.62.63.92.exe
Download: download sample
Signature Blackmoon
File size:856'576 bytes
First seen:2024-05-07 01:18:54 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash ffb169cf03ac3d4750dd8e3783007a92 (5 x Blackmoon)
ssdeep 24576:TFYLJfZXhoXnH0WahXUvK3QyOOrTxW7+EmTRR3QxgGVLWv2Pxw:TSBL43P2
Threatray 783 similar samples on MalwareBazaar
TLSH T1AC053A237221C0A3C1612FF957AA163838F847152D79A963AFD8AEA67CB4533CF3550D
TrID 38.1% (.CPL) Windows Control Panel Item (generic) (57583/11/19)
20.6% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
10.9% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
8.6% (.SCR) Windows screen saver (13097/50/3)
6.9% (.EXE) Win64 Executable (generic) (10523/12/4)
File icon (PE):PE icon
dhash icon ccaa33cacab3b2ec (15 x Blackmoon, 1 x Gh0stRAT)
Reporter bobross_malware2
Tags:Blackmoon exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
305
Origin country :
US US
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
145af39418607f9a21c35aaa855b65e8019c4d35750cb70d515f9807b43a3f21.exe
Verdict:
Suspicious activity
Analysis date:
2024-05-07 01:23:04 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Creating a window
Connection attempt
Sending an HTTP GET request
Result
Threat name:
BlackMoon
Detection:
malicious
Classification:
rans
Score:
76 / 100
Signature
Antivirus / Scanner detection for submitted sample
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected BlackMoon Ransomware
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2024-05-06 17:55:55 UTC
File Type:
PE (Exe)
Extracted files:
8
AV detection:
27 of 38 (71.05%)
Threat level:
  5/5
Result
Malware family:
blackmoon
Score:
  10/10
Tags:
family:blackmoon banker persistence trojan
Behaviour
Modifies Control Panel
Suspicious use of AdjustPrivilegeToken
Sets file execution options in registry
Blackmoon, KrBanker
Detect Blackmoon payload
Unpacked files
SH256 hash:
a8b191e27be3c026d5170f995f447f8d7da114faed86820b639434f836d0379c
MD5 hash:
bce4733c6eb5ebaec06cd23a28f059a1
SHA1 hash:
02dacfb3c952f1c94540505e292ad0d444504a51
SH256 hash:
97ea3d99cf21123bc1aec72f9ded6a51ac659830392adfefd424eb799ab0219e
MD5 hash:
8b3591965f623b219c0c528153746cab
SHA1 hash:
020961494fa0e08779b7aacf4422269935354f7d
SH256 hash:
11c46cb8f4208fd25c77cdc688204f3252b07b50c481c15454af745652d60784
MD5 hash:
01c05ffcec63e010eec4425c304ed371
SHA1 hash:
8d5ed0c3e4ed87f954d57be041e7ee366cd99350
SH256 hash:
145af39418607f9a21c35aaa855b65e8019c4d35750cb70d515f9807b43a3f21
MD5 hash:
b4b622dd6692b0185bd1a284ac849d2f
SHA1 hash:
5043b80e44a14c704abbabe58c3c405c255c6a87
Detections:
BlackmoonBanker MALWARE_Win_BlackMoon
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerHiding__Thread
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:HeavensGate
Author:kevoreilly
Description:Heaven's Gate: Switch from 32-bit to 64-mode
Rule name:maldoc_find_kernel32_base_method_1
Author:Didier Stevens (https://DidierStevens.com)
Rule name:maldoc_getEIP_method_1
Author:Didier Stevens (https://DidierStevens.com)
Rule name:MALWARE_Win_BlackMoon
Author:ditekSHen
Description:Detects executables using BlackMoon RunTime
Rule name:meth_get_eip
Author:Willi Ballenthin
Rule name:meth_peb_parsing
Author:Willi Ballenthin
Rule name:PE_Potentially_Signed_Digital_Certificate
Author:albertzsigovits
Rule name:UPXV200V290MarkusOberhumerLaszloMolnarJohnReiser
Author:malware-lu
Rule name:Windows_Trojan_CobaltStrike_f0b627fc
Description:Rule for beacon reflective loader
Rule name:Windows_Trojan_CobaltStrike_f0b627fc
Author:Elastic Security
Description:Rule for beacon reflective loader

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Blackmoon

Executable exe 145af39418607f9a21c35aaa855b65e8019c4d35750cb70d515f9807b43a3f21

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
CHECK_TRUST_INFORequires Elevated Execution (level:requireAdministrator)high
Reviews
IDCapabilitiesEvidence
COM_BASE_APICan Download & Execute componentsole32.dll::CreateStreamOnHGlobal
DP_APIUses DP APICRYPT32.dll::CryptProtectData
GDI_PLUS_APIInterfaces with Graphicsgdiplus.dll::GdiplusStartup
gdiplus.dll::GdipGetImageEncodersSize
gdiplus.dll::GdipGetImageEncoders
gdiplus.dll::GdipDeleteGraphics
gdiplus.dll::GdipFillRectangle
gdiplus.dll::GdipDeleteBrush
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.DLL::CreateProcessA
KERNEL32.DLL::CloseHandle
WINHTTP.dll::WinHttpCloseHandle
KERNEL32.DLL::CreateThread
WIN_BASE_APIUses Win Base APIKERNEL32.DLL::LoadLibraryA
KERNEL32.DLL::GetStartupInfoA
KERNEL32.DLL::GetCommandLineA
KERNEL32.DLL::GetCommandLineW
WIN_BASE_IO_APICan Create FilesKERNEL32.DLL::CreateDirectoryA
KERNEL32.DLL::CreateDirectoryW
KERNEL32.DLL::CreateFileA
KERNEL32.DLL::DeleteFileA
KERNEL32.DLL::MoveFileA
SHLWAPI.dll::PathRemoveFileSpecW
WIN_HTTP_APIUses HTTP servicesWINHTTP.dll::WinHttpAddRequestHeaders
WINHTTP.dll::WinHttpConnect
WINHTTP.dll::WinHttpCrackUrl
WINHTTP.dll::WinHttpOpenRequest
WINHTTP.dll::WinHttpOpen
WINHTTP.dll::WinHttpQueryDataAvailable
WIN_REG_APICan Manipulate Windows RegistryADVAPI32.dll::RegCreateKeyExA
ADVAPI32.dll::RegDeleteKeyA
ADVAPI32.dll::RegOpenKeyA
ADVAPI32.dll::RegOpenKeyExA
ADVAPI32.dll::RegQueryValueExA
ADVAPI32.dll::RegSetValueExA
WIN_SVC_APICan Manipulate Windows ServicesADVAPI32.dll::ControlService
ADVAPI32.dll::CreateServiceA
ADVAPI32.dll::OpenSCManagerA
ADVAPI32.dll::OpenServiceA
ADVAPI32.dll::StartServiceA
WIN_USER_APIPerforms GUI ActionsUSER32.dll::AppendMenuW
USER32.dll::CreateMenu
USER32.dll::FindWindowExA
USER32.dll::FindWindowExW
USER32.dll::PeekMessageA
USER32.dll::CreateWindowExW

Comments