General

  • Target

    1521c65db96107b65b083eab22f7fc52a5b3604491beb36c69393922c11ac90d

  • Size

    163KB

  • Sample

    240629-xf51gatbrg

  • MD5

    ef319813f68a56fb666df2b1cc7d94cb

  • SHA1

    18f8d1d55c48c45018c2f81919a4f8ee3143d1ed

  • SHA256

    1521c65db96107b65b083eab22f7fc52a5b3604491beb36c69393922c11ac90d

  • SHA512

    9cf17c746a23120c50b9163415c55667b79aed5ccd8449f947a659d5749598c7eada6eff3a6da4cefa633bb66002c4704e48affd357d8500fffbad12a169b7fd

  • SSDEEP

    1536:PrPha/IUhAB769XNniz2j6VBvqkfBZmebk+r/nwVlProNVU4qNVUrk/9QbfBr+7g:D2Mu9sz223vKenPqltOrWKDBr+yJb

Malware Config

Extracted

Family

gozi

Targets

    • Target

      1521c65db96107b65b083eab22f7fc52a5b3604491beb36c69393922c11ac90d

    • Size

      163KB

    • MD5

      ef319813f68a56fb666df2b1cc7d94cb

    • SHA1

      18f8d1d55c48c45018c2f81919a4f8ee3143d1ed

    • SHA256

      1521c65db96107b65b083eab22f7fc52a5b3604491beb36c69393922c11ac90d

    • SHA512

      9cf17c746a23120c50b9163415c55667b79aed5ccd8449f947a659d5749598c7eada6eff3a6da4cefa633bb66002c4704e48affd357d8500fffbad12a169b7fd

    • SSDEEP

      1536:PrPha/IUhAB769XNniz2j6VBvqkfBZmebk+r/nwVlProNVU4qNVUrk/9QbfBr+7g:D2Mu9sz223vKenPqltOrWKDBr+yJb

    • Adds autorun key to be loaded by Explorer.exe on startup

    • Gozi

      Gozi is a well-known and widely distributed banking trojan.

    • Detects executables built or packed with MPress PE compressor

    • UPX dump on OEP (original entry point)

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks