Rewterz
Rewterz Threat Alert – FormBook Malware – Active IOCs
March 28, 2022
Rewterz
Rewterz Threat Alert – Agent Tesla Malware – Active IOCs
March 28, 2022

Rewterz Threat Alert – BlackMoon Banking Trojan – Active IOCs

Severity

High

Analysis Summary

BlackMoon, aka KRBanker, is a banking trojan it can steal financial and banking account information as well as other sensitive data. Blackmoon was discovered in 2014 by Fortinet researchers, and it is back again with a new campaign. Blackmoon used to attack the host with URLs, advertisements, and other web content. Once the host has been compromised it can open multiple pop-ups.

Impact

  • Credential Theft
  • Financial Loss
  • Data Exfiltration

Indicators of Compromise

MD5

  • abd386bd13baa8922393cdc627e4f8e3
  • e77bbf34e50a3573e1a1dee4b9c1f6d8

SHA-256

  • cdc98e5891eeb209b04680f8c32981c3c4dd64240f01e98b35efaa1d43f15bc7
  • e9c321d5987986c891aee1d2e0aa5f06f406b7994a62cee0820c70b4f2e265c4

SHA-1

  • 088694457cc5727bd1aaf61ad65405f3cbbce7d5
  • 0b86d2a2feeaa384493ede9ed568a144cd4af16f

Remediation

  • Block all the threat indicators at your respective controls.
  • Search for IOCs in your environment.