General

  • Target

    e8988ec96b831d7609264dc3af2e3efbe6a86e57b53ee50d7343bc94a0fc4a43

  • Size

    163KB

  • Sample

    240629-e5qmzatgmk

  • MD5

    7cc42d8d018f151aa86e71b4b4dd7f00

  • SHA1

    31fa9f66c9344de1c0fce14a70a5ebf4313b22c5

  • SHA256

    e8988ec96b831d7609264dc3af2e3efbe6a86e57b53ee50d7343bc94a0fc4a43

  • SHA512

    3799817dd1eae3cb50c4200efa8f5d5194bfd45bb3f82dc15d9f7f0654db5f4209ee7c3998fa3c4db8a8015bb309ca705e944eafa0e830f55753b7c66bb4eeb4

  • SSDEEP

    3072:6Fc9xik1wLvEqPY2yhIqAZ77luvleltOrWKDBr+yJb:iPA+qa7RuvleLOf

Malware Config

Extracted

Family

gozi

Targets

    • Target

      e8988ec96b831d7609264dc3af2e3efbe6a86e57b53ee50d7343bc94a0fc4a43

    • Size

      163KB

    • MD5

      7cc42d8d018f151aa86e71b4b4dd7f00

    • SHA1

      31fa9f66c9344de1c0fce14a70a5ebf4313b22c5

    • SHA256

      e8988ec96b831d7609264dc3af2e3efbe6a86e57b53ee50d7343bc94a0fc4a43

    • SHA512

      3799817dd1eae3cb50c4200efa8f5d5194bfd45bb3f82dc15d9f7f0654db5f4209ee7c3998fa3c4db8a8015bb309ca705e944eafa0e830f55753b7c66bb4eeb4

    • SSDEEP

      3072:6Fc9xik1wLvEqPY2yhIqAZ77luvleltOrWKDBr+yJb:iPA+qa7RuvleLOf

    • Adds autorun key to be loaded by Explorer.exe on startup

    • Gozi

      Gozi is a well-known and widely distributed banking trojan.

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks