General

  • Target

    3b3bbf18245401eed60bcfffeb3ebb90837f5f02807d66ffc79dd4efc88e8ba8

  • Size

    5.0MB

  • Sample

    240630-e2ljvatfkf

  • MD5

    db1219522d8d190329b99e84cc5360d9

  • SHA1

    542bc9f5af17506fcbc4e19cb8eeb44f9e03c188

  • SHA256

    3b3bbf18245401eed60bcfffeb3ebb90837f5f02807d66ffc79dd4efc88e8ba8

  • SHA512

    c9c4758defd0deedd3ab86e210168bffd96ffeca4dfc967a231c9ac83eb54929d65c1955050e842f56c36a12c62bf71065beb8d23d412629210873fe9b7ef1b1

  • SSDEEP

    98304:CNJOl1ts0XYJqT+q3bhp+O5WN4oO8HjMIrHOPHXJ6AGC6jAUBMdfQxIc:91K0XYwTh9k6NorYpHXJS1uQn

Malware Config

Targets

    • Target

      3b3bbf18245401eed60bcfffeb3ebb90837f5f02807d66ffc79dd4efc88e8ba8

    • Size

      5.0MB

    • MD5

      db1219522d8d190329b99e84cc5360d9

    • SHA1

      542bc9f5af17506fcbc4e19cb8eeb44f9e03c188

    • SHA256

      3b3bbf18245401eed60bcfffeb3ebb90837f5f02807d66ffc79dd4efc88e8ba8

    • SHA512

      c9c4758defd0deedd3ab86e210168bffd96ffeca4dfc967a231c9ac83eb54929d65c1955050e842f56c36a12c62bf71065beb8d23d412629210873fe9b7ef1b1

    • SSDEEP

      98304:CNJOl1ts0XYJqT+q3bhp+O5WN4oO8HjMIrHOPHXJ6AGC6jAUBMdfQxIc:91K0XYwTh9k6NorYpHXJS1uQn

    • Detect Socks5Systemz Payload

    • Socks5Systemz

      Socks5Systemz is a botnet written in C++.

    • Executes dropped EXE

    • Loads dropped DLL

    • Unexpected DNS network traffic destination

      Network traffic to other servers than the configured DNS servers was detected on the DNS port.

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

1
T1082

Tasks