General

  • Target

    b91fec1f73b46d2b747f206707dd0301deeaf06a2a06087b3c0bc4737f8f4557

  • Size

    163KB

  • Sample

    240625-b4yemsteng

  • MD5

    f7362d6df73c2c1db4a1e25e8dafd8a3

  • SHA1

    d160b1aa07b06045bffecd86ad495a41fd407706

  • SHA256

    b91fec1f73b46d2b747f206707dd0301deeaf06a2a06087b3c0bc4737f8f4557

  • SHA512

    13e377a4bac7b5a45ecce34871ce94dbdd74de75c63e8f7b7b8bd12d7ef07018a0fe6e3be9b975eafd0112d658dbaafb0822e1a77326dc7ab474791c45c008d3

  • SSDEEP

    1536:PRZZV4Oz6bdI543vDOW4ImlProNVU4qNVUrk/9QbfBr+7GwKrPAsqNVU:pPVbz625277jmltOrWKDBr+yJb

Malware Config

Extracted

Family

gozi

Targets

    • Target

      b91fec1f73b46d2b747f206707dd0301deeaf06a2a06087b3c0bc4737f8f4557

    • Size

      163KB

    • MD5

      f7362d6df73c2c1db4a1e25e8dafd8a3

    • SHA1

      d160b1aa07b06045bffecd86ad495a41fd407706

    • SHA256

      b91fec1f73b46d2b747f206707dd0301deeaf06a2a06087b3c0bc4737f8f4557

    • SHA512

      13e377a4bac7b5a45ecce34871ce94dbdd74de75c63e8f7b7b8bd12d7ef07018a0fe6e3be9b975eafd0112d658dbaafb0822e1a77326dc7ab474791c45c008d3

    • SSDEEP

      1536:PRZZV4Oz6bdI543vDOW4ImlProNVU4qNVUrk/9QbfBr+7GwKrPAsqNVU:pPVbz625277jmltOrWKDBr+yJb

    • Adds autorun key to be loaded by Explorer.exe on startup

    • Gozi

      Gozi is a well-known and widely distributed banking trojan.

    • Detects executables built or packed with MPress PE compressor

    • UPX dump on OEP (original entry point)

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks