General

  • Target

    e4a80728e6f8efdefc6f75560196ceda43d8835b1038feccd6b132cbc6ff6b5b

  • Size

    9.3MB

  • Sample

    240629-pkc69axdne

  • MD5

    a8b40d4763f08d51bfed24d0bf258d0a

  • SHA1

    2d949f75673e7489ccdabb266134a951dbf5586f

  • SHA256

    e4a80728e6f8efdefc6f75560196ceda43d8835b1038feccd6b132cbc6ff6b5b

  • SHA512

    7ad834243e35af6ecdafe253bffc7b80d2020737e92ad0a82fbb881fde4506c7e6759e05e114ece6c91eda6f3877d4b6ede4a11d73ec4b20b383648b5f42f5c9

  • SSDEEP

    196608:nPRWJbVQPXVB6F9xnRE3PHBDmsqfMcTKyb0qJQmhp:og/VB3VEdsC7

Score
10/10

Malware Config

Extracted

Family

gozi

Targets

    • Target

      e4a80728e6f8efdefc6f75560196ceda43d8835b1038feccd6b132cbc6ff6b5b

    • Size

      9.3MB

    • MD5

      a8b40d4763f08d51bfed24d0bf258d0a

    • SHA1

      2d949f75673e7489ccdabb266134a951dbf5586f

    • SHA256

      e4a80728e6f8efdefc6f75560196ceda43d8835b1038feccd6b132cbc6ff6b5b

    • SHA512

      7ad834243e35af6ecdafe253bffc7b80d2020737e92ad0a82fbb881fde4506c7e6759e05e114ece6c91eda6f3877d4b6ede4a11d73ec4b20b383648b5f42f5c9

    • SSDEEP

      196608:nPRWJbVQPXVB6F9xnRE3PHBDmsqfMcTKyb0qJQmhp:og/VB3VEdsC7

    Score
    7/10
    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Drops file in System32 directory

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Modify Registry

1
T1112

Discovery

Query Registry

2
T1012

System Information Discovery

3
T1082

Tasks