General

  • Target

    49077ae84375c6c95a50cc03f9ccb462007955fee99eb6870c47a81a1818494e

  • Size

    5.0MB

  • Sample

    240630-255s8asamq

  • MD5

    c857ab52ba2b14060bc22eb969f45db3

  • SHA1

    f8538edc200faf30c7874750afde3d7a0e460de0

  • SHA256

    49077ae84375c6c95a50cc03f9ccb462007955fee99eb6870c47a81a1818494e

  • SHA512

    1e3de873a9c6aeb1d2d34ca6b2faaaefdbedd0f664574cc9abf53ea4a03e31b1c203a368adf985ed089ffd72069432db6b0a6087ca6c5d734db4a1b40e8661b2

  • SSDEEP

    98304:CUJwisMXxpIFBsRiZpWfTQhM1SYQsEBkholgYowu5MrPsRxFpMBQx7:zHqB88kL3UY5oOylPsRxAQt

Malware Config

Targets

    • Target

      49077ae84375c6c95a50cc03f9ccb462007955fee99eb6870c47a81a1818494e

    • Size

      5.0MB

    • MD5

      c857ab52ba2b14060bc22eb969f45db3

    • SHA1

      f8538edc200faf30c7874750afde3d7a0e460de0

    • SHA256

      49077ae84375c6c95a50cc03f9ccb462007955fee99eb6870c47a81a1818494e

    • SHA512

      1e3de873a9c6aeb1d2d34ca6b2faaaefdbedd0f664574cc9abf53ea4a03e31b1c203a368adf985ed089ffd72069432db6b0a6087ca6c5d734db4a1b40e8661b2

    • SSDEEP

      98304:CUJwisMXxpIFBsRiZpWfTQhM1SYQsEBkholgYowu5MrPsRxFpMBQx7:zHqB88kL3UY5oOylPsRxAQt

    • Detect Socks5Systemz Payload

    • Socks5Systemz

      Socks5Systemz is a botnet written in C++.

    • Executes dropped EXE

    • Loads dropped DLL

    • Unexpected DNS network traffic destination

      Network traffic to other servers than the configured DNS servers was detected on the DNS port.

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

1
T1082

Tasks