General

  • Target

    79f0fa9f91a1b2205f6ff58997f82b422c0b636c82470a55c0ba98c1e1539166

  • Size

    163KB

  • Sample

    240616-2vj4rswejl

  • MD5

    571fc61d185519b537075f746c316064

  • SHA1

    21a8d9676d926a8080d2154375a7e07277a3a0fc

  • SHA256

    79f0fa9f91a1b2205f6ff58997f82b422c0b636c82470a55c0ba98c1e1539166

  • SHA512

    1fd741427744c64523a5bcad74890c47c845ca88c32e411a58d622f7d42df0c9d0486eb36f08d5a8d50ce8371a0087c134c98215007831e9c83219c15c2be754

  • SSDEEP

    1536:P5VJDvLShJo/599BUreEUCJwyzJlProNVU4qNVUrk/9QbfBr+7GwKrPAsqNVU:xrt99BUrwcJltOrWKDBr+yJb

Malware Config

Extracted

Family

gozi

Targets

    • Target

      79f0fa9f91a1b2205f6ff58997f82b422c0b636c82470a55c0ba98c1e1539166

    • Size

      163KB

    • MD5

      571fc61d185519b537075f746c316064

    • SHA1

      21a8d9676d926a8080d2154375a7e07277a3a0fc

    • SHA256

      79f0fa9f91a1b2205f6ff58997f82b422c0b636c82470a55c0ba98c1e1539166

    • SHA512

      1fd741427744c64523a5bcad74890c47c845ca88c32e411a58d622f7d42df0c9d0486eb36f08d5a8d50ce8371a0087c134c98215007831e9c83219c15c2be754

    • SSDEEP

      1536:P5VJDvLShJo/599BUreEUCJwyzJlProNVU4qNVUrk/9QbfBr+7GwKrPAsqNVU:xrt99BUrwcJltOrWKDBr+yJb

    • Adds autorun key to be loaded by Explorer.exe on startup

    • Gozi

      Gozi is a well-known and widely distributed banking trojan.

    • Detects executables built or packed with MPress PE compressor

    • UPX dump on OEP (original entry point)

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks