General

  • Target

    542b136be9be4163b79bebf57ab96fdc2758b2fcd1445bf982bfc6082fcde9c3

  • Size

    5.1MB

  • Sample

    240628-g3r45avfmf

  • MD5

    fae36e468a10217c69b9b782852e6e14

  • SHA1

    d55e9094fa4fa5cafd01673d3f431a677857299a

  • SHA256

    542b136be9be4163b79bebf57ab96fdc2758b2fcd1445bf982bfc6082fcde9c3

  • SHA512

    11684ea826fa2a05d741dfca20d08a48513de0614f4d60b8d921fc8bb401793273b77caf5c54c2d5e980f18be51b80fb743d37b6f70d99b0e2d1b6322ab1eae0

  • SSDEEP

    98304:Cg/KXyZxOyHk0jsfiT2ICI/YcQFmoifcGOGLq8mDIlR2r8N/FscxlyemK996lQxE:nLZxOyHkkvidcQFwcc28mk/24N9scx2D

Malware Config

Targets

    • Target

      542b136be9be4163b79bebf57ab96fdc2758b2fcd1445bf982bfc6082fcde9c3

    • Size

      5.1MB

    • MD5

      fae36e468a10217c69b9b782852e6e14

    • SHA1

      d55e9094fa4fa5cafd01673d3f431a677857299a

    • SHA256

      542b136be9be4163b79bebf57ab96fdc2758b2fcd1445bf982bfc6082fcde9c3

    • SHA512

      11684ea826fa2a05d741dfca20d08a48513de0614f4d60b8d921fc8bb401793273b77caf5c54c2d5e980f18be51b80fb743d37b6f70d99b0e2d1b6322ab1eae0

    • SSDEEP

      98304:Cg/KXyZxOyHk0jsfiT2ICI/YcQFmoifcGOGLq8mDIlR2r8N/FscxlyemK996lQxE:nLZxOyHkkvidcQFwcc28mk/24N9scx2D

    • Detect Socks5Systemz Payload

    • Socks5Systemz

      Socks5Systemz is a botnet written in C++.

    • Executes dropped EXE

    • Loads dropped DLL

    • Unexpected DNS network traffic destination

      Network traffic to other servers than the configured DNS servers was detected on the DNS port.

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

1
T1082

Tasks