General

  • Target

    1aa1d7b1a5d218cdae38b78fb5389e7970944062576f8bfb3a1f25c69cacd82a

  • Size

    245KB

  • Sample

    240623-x47h7stamp

  • MD5

    2c78b21bb972ad276686f84045379740

  • SHA1

    b4cdb289f0224ab091d3c6c610664db3f1acf763

  • SHA256

    1aa1d7b1a5d218cdae38b78fb5389e7970944062576f8bfb3a1f25c69cacd82a

  • SHA512

    d5c3f48ead39125827e7fc6049e436d9c86bb82895913364189fafd72341608b3449e04d57d394239f30717530d7acdce37abbc3bb21b41f2c5f4e0083b54e65

  • SSDEEP

    1536:204TBvVULpxtOWk/PI5Gb2wi/4cXeXvubKrFEwMEwKhbArEwKhQL4cXeXvubKr:kBvVUtxtOW9ob2wiwago+bAr+Qka

Malware Config

Extracted

Family

gozi

Targets

    • Target

      1aa1d7b1a5d218cdae38b78fb5389e7970944062576f8bfb3a1f25c69cacd82a

    • Size

      245KB

    • MD5

      2c78b21bb972ad276686f84045379740

    • SHA1

      b4cdb289f0224ab091d3c6c610664db3f1acf763

    • SHA256

      1aa1d7b1a5d218cdae38b78fb5389e7970944062576f8bfb3a1f25c69cacd82a

    • SHA512

      d5c3f48ead39125827e7fc6049e436d9c86bb82895913364189fafd72341608b3449e04d57d394239f30717530d7acdce37abbc3bb21b41f2c5f4e0083b54e65

    • SSDEEP

      1536:204TBvVULpxtOWk/PI5Gb2wi/4cXeXvubKrFEwMEwKhbArEwKhQL4cXeXvubKr:kBvVUtxtOW9ob2wiwago+bAr+Qka

    • Adds autorun key to be loaded by Explorer.exe on startup

    • Gozi

      Gozi is a well-known and widely distributed banking trojan.

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks