General

  • Target

    b4bae79bb28b1f8bcabbb5ba1bcd43809997029de1bb5c9d0c3900fde99272e7

  • Size

    5.2MB

  • Sample

    240629-zcsbbawakh

  • MD5

    9510b222bfe811a0e9cb84324deab879

  • SHA1

    0baa5dfb98f1b56c45e560bfa755123c9631f22c

  • SHA256

    b4bae79bb28b1f8bcabbb5ba1bcd43809997029de1bb5c9d0c3900fde99272e7

  • SHA512

    56425a7ecef65418dc85b6ae315b3ce8ff25f151d4c7bfe4e10209c0b466b6157cab73a38004a98a4bc5adc977079fbdd31c34d01004766e80d5b107e140f37e

  • SSDEEP

    98304:Cmd9RXB2d75+/2UTq8Z+T0ics1UPPIYZk3xGaZsmbOqLT6P8fp0PsS1eQx9W:7AlKTq77nCPvK3ovFeThh2eQa

Malware Config

Targets

    • Target

      b4bae79bb28b1f8bcabbb5ba1bcd43809997029de1bb5c9d0c3900fde99272e7

    • Size

      5.2MB

    • MD5

      9510b222bfe811a0e9cb84324deab879

    • SHA1

      0baa5dfb98f1b56c45e560bfa755123c9631f22c

    • SHA256

      b4bae79bb28b1f8bcabbb5ba1bcd43809997029de1bb5c9d0c3900fde99272e7

    • SHA512

      56425a7ecef65418dc85b6ae315b3ce8ff25f151d4c7bfe4e10209c0b466b6157cab73a38004a98a4bc5adc977079fbdd31c34d01004766e80d5b107e140f37e

    • SSDEEP

      98304:Cmd9RXB2d75+/2UTq8Z+T0ics1UPPIYZk3xGaZsmbOqLT6P8fp0PsS1eQx9W:7AlKTq77nCPvK3ovFeThh2eQa

    • Detect Socks5Systemz Payload

    • Socks5Systemz

      Socks5Systemz is a botnet written in C++.

    • Executes dropped EXE

    • Loads dropped DLL

    • Unexpected DNS network traffic destination

      Network traffic to other servers than the configured DNS servers was detected on the DNS port.

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

1
T1082

Tasks