General

  • Target

    9006ca9284c27db7c2e11ecd4c58d6a3f3998a1b6fe3d3bad3d87230fd0eef4e

  • Size

    5.0MB

  • Sample

    240630-b2tnns1hqc

  • MD5

    edea13663cf40597874231b0fd500620

  • SHA1

    348661f837ff505910acb221904948da8b665730

  • SHA256

    9006ca9284c27db7c2e11ecd4c58d6a3f3998a1b6fe3d3bad3d87230fd0eef4e

  • SHA512

    49e3b14b0d3a146fd5ddf5fd631a90653b9311a2aa912513fb06d8beee10337d9866d29587cccb43c78596ff75b063fbb8dc57b54754fab9989034d0c77ec244

  • SSDEEP

    98304:CLArG4EKqpZBd9GaEGb8/dO6g/vJY6VqJ36eej7rWcL9xrUm7LmQx9W:jlJqpHZdgFOdVVqJ9ej7rT1LmQa

Malware Config

Targets

    • Target

      9006ca9284c27db7c2e11ecd4c58d6a3f3998a1b6fe3d3bad3d87230fd0eef4e

    • Size

      5.0MB

    • MD5

      edea13663cf40597874231b0fd500620

    • SHA1

      348661f837ff505910acb221904948da8b665730

    • SHA256

      9006ca9284c27db7c2e11ecd4c58d6a3f3998a1b6fe3d3bad3d87230fd0eef4e

    • SHA512

      49e3b14b0d3a146fd5ddf5fd631a90653b9311a2aa912513fb06d8beee10337d9866d29587cccb43c78596ff75b063fbb8dc57b54754fab9989034d0c77ec244

    • SSDEEP

      98304:CLArG4EKqpZBd9GaEGb8/dO6g/vJY6VqJ36eej7rWcL9xrUm7LmQx9W:jlJqpHZdgFOdVVqJ9ej7rT1LmQa

    • Detect Socks5Systemz Payload

    • Socks5Systemz

      Socks5Systemz is a botnet written in C++.

    • Executes dropped EXE

    • Loads dropped DLL

    • Unexpected DNS network traffic destination

      Network traffic to other servers than the configured DNS servers was detected on the DNS port.

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

1
T1082

Tasks