General

  • Target

    a56624227ba1678fcc42de8f327b2bbd3c88752553c7412417be7ce0e4f016ab

  • Size

    5.0MB

  • Sample

    240630-f9b6taxeqn

  • MD5

    055eada1317e5e0ea51dc0da5d64f513

  • SHA1

    e31e7a97e83e3b52d8d9518385946268353ea3c4

  • SHA256

    a56624227ba1678fcc42de8f327b2bbd3c88752553c7412417be7ce0e4f016ab

  • SHA512

    6c9dde94e0422694fa90cb9669e2808f3a2bdb3811a462bf561ed69cd509b479392a6c167d771eaceb3657d73c40c87dd40f33dbbad14e9aa444258ae55e0a8d

  • SSDEEP

    98304:Cw8mf2SXtjj5R8MfwR12Xbo2u0wG0r7xoiT5RusF87b0KD0zssZXydQxIc:78mf2SXtfIhCLo30w/rCRl7bCXuQn

Malware Config

Targets

    • Target

      a56624227ba1678fcc42de8f327b2bbd3c88752553c7412417be7ce0e4f016ab

    • Size

      5.0MB

    • MD5

      055eada1317e5e0ea51dc0da5d64f513

    • SHA1

      e31e7a97e83e3b52d8d9518385946268353ea3c4

    • SHA256

      a56624227ba1678fcc42de8f327b2bbd3c88752553c7412417be7ce0e4f016ab

    • SHA512

      6c9dde94e0422694fa90cb9669e2808f3a2bdb3811a462bf561ed69cd509b479392a6c167d771eaceb3657d73c40c87dd40f33dbbad14e9aa444258ae55e0a8d

    • SSDEEP

      98304:Cw8mf2SXtjj5R8MfwR12Xbo2u0wG0r7xoiT5RusF87b0KD0zssZXydQxIc:78mf2SXtfIhCLo30w/rCRl7bCXuQn

    • Detect Socks5Systemz Payload

    • Socks5Systemz

      Socks5Systemz is a botnet written in C++.

    • Executes dropped EXE

    • Loads dropped DLL

    • Unexpected DNS network traffic destination

      Network traffic to other servers than the configured DNS servers was detected on the DNS port.

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

1
T1082

Tasks