General

  • Target

    59b3c7e8759f3b1f80003e156d18fcc4f1722b8454f3c84fd76393a75f9c8f19

  • Size

    4.9MB

  • Sample

    240629-bcmttsxapb

  • MD5

    8b77b44d6afbc5c186da935044b578d3

  • SHA1

    22904c3906df4f8a17e1b6682d23292c1b82b0b7

  • SHA256

    59b3c7e8759f3b1f80003e156d18fcc4f1722b8454f3c84fd76393a75f9c8f19

  • SHA512

    387888850006709d9c3cd8172cb26b55725a9b73c257356ceb568bbeee2ac1e1a2f03f67abedd2ed2013066331c5838b981f472dfd5c3f780f2f9e266b847e36

  • SSDEEP

    98304:Crcg0Gfdf/hRxXLdH37sSqp/uagBkKeAurnv16axQesV7CMxGPsWbNOoE9hQxg:w0Gfdf/fxbducvBkK1urnN3T4rWbNOnZ

Malware Config

Targets

    • Target

      59b3c7e8759f3b1f80003e156d18fcc4f1722b8454f3c84fd76393a75f9c8f19

    • Size

      4.9MB

    • MD5

      8b77b44d6afbc5c186da935044b578d3

    • SHA1

      22904c3906df4f8a17e1b6682d23292c1b82b0b7

    • SHA256

      59b3c7e8759f3b1f80003e156d18fcc4f1722b8454f3c84fd76393a75f9c8f19

    • SHA512

      387888850006709d9c3cd8172cb26b55725a9b73c257356ceb568bbeee2ac1e1a2f03f67abedd2ed2013066331c5838b981f472dfd5c3f780f2f9e266b847e36

    • SSDEEP

      98304:Crcg0Gfdf/hRxXLdH37sSqp/uagBkKeAurnv16axQesV7CMxGPsWbNOoE9hQxg:w0Gfdf/fxbducvBkK1urnN3T4rWbNOnZ

    • Detect Socks5Systemz Payload

    • Socks5Systemz

      Socks5Systemz is a botnet written in C++.

    • Executes dropped EXE

    • Loads dropped DLL

    • Unexpected DNS network traffic destination

      Network traffic to other servers than the configured DNS servers was detected on the DNS port.

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

1
T1082

Tasks