General

  • Target

    056acc8eb20691561e49daf5b2d621a4f4428039d6e26d560720cc972edc5296

  • Size

    4.9MB

  • Sample

    240628-3h2zgsverh

  • MD5

    b9dd1636c968d62dc29652e5767dd2d8

  • SHA1

    5bbdb6228d27bb8f155fae17a697cbe6b01869ba

  • SHA256

    056acc8eb20691561e49daf5b2d621a4f4428039d6e26d560720cc972edc5296

  • SHA512

    bd61ef575db0d3be663ad9bb85039b9868dc9d178de6803ca4edf4ee86c2a00f203871d5552d9751ca24846cbb8c4f27613912b75f29bfc4b2cb8b291f2e3a7c

  • SSDEEP

    98304:CPqGAWvkNrerFtNTLPJTtFndJUu8UkNsjPBZb5N0dmqrVMQxg:9W2er5jJTtPJRsNsrH5NGmqreQC

Malware Config

Targets

    • Target

      056acc8eb20691561e49daf5b2d621a4f4428039d6e26d560720cc972edc5296

    • Size

      4.9MB

    • MD5

      b9dd1636c968d62dc29652e5767dd2d8

    • SHA1

      5bbdb6228d27bb8f155fae17a697cbe6b01869ba

    • SHA256

      056acc8eb20691561e49daf5b2d621a4f4428039d6e26d560720cc972edc5296

    • SHA512

      bd61ef575db0d3be663ad9bb85039b9868dc9d178de6803ca4edf4ee86c2a00f203871d5552d9751ca24846cbb8c4f27613912b75f29bfc4b2cb8b291f2e3a7c

    • SSDEEP

      98304:CPqGAWvkNrerFtNTLPJTtFndJUu8UkNsjPBZb5N0dmqrVMQxg:9W2er5jJTtPJRsNsrH5NGmqreQC

    • Detect Socks5Systemz Payload

    • Socks5Systemz

      Socks5Systemz is a botnet written in C++.

    • Executes dropped EXE

    • Loads dropped DLL

    • Unexpected DNS network traffic destination

      Network traffic to other servers than the configured DNS servers was detected on the DNS port.

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

1
T1082

Tasks