General

  • Target

    fa7f568e4c74682f6729a954d4467c36c0a7eb14543599faf8976b110df575c3

  • Size

    5.0MB

  • Sample

    240630-neay9sxakg

  • MD5

    6938d335b97b09dc5156962aab78c06d

  • SHA1

    923af25eb9c83da9341eeec63c1bbcd085a155d7

  • SHA256

    fa7f568e4c74682f6729a954d4467c36c0a7eb14543599faf8976b110df575c3

  • SHA512

    82acf07c5c5c127c5754c1b58dd1017cb0c1887bba711abe17c1f6b17e585af0064388ced46c0cedf7af40d20b6f0f720c116cdf7efdae167d3634008866e50e

  • SSDEEP

    98304:Ct6BkS34hNqL9KOmM88OVC0YTUB7JAJIQFoeS/NM1f9tMakCYqQxE:ExSohNqL8Om2OkBO7GuGopMd9tMmFQ2

Malware Config

Targets

    • Target

      fa7f568e4c74682f6729a954d4467c36c0a7eb14543599faf8976b110df575c3

    • Size

      5.0MB

    • MD5

      6938d335b97b09dc5156962aab78c06d

    • SHA1

      923af25eb9c83da9341eeec63c1bbcd085a155d7

    • SHA256

      fa7f568e4c74682f6729a954d4467c36c0a7eb14543599faf8976b110df575c3

    • SHA512

      82acf07c5c5c127c5754c1b58dd1017cb0c1887bba711abe17c1f6b17e585af0064388ced46c0cedf7af40d20b6f0f720c116cdf7efdae167d3634008866e50e

    • SSDEEP

      98304:Ct6BkS34hNqL9KOmM88OVC0YTUB7JAJIQFoeS/NM1f9tMakCYqQxE:ExSohNqL8Om2OkBO7GuGopMd9tMmFQ2

    • Detect Socks5Systemz Payload

    • Socks5Systemz

      Socks5Systemz is a botnet written in C++.

    • Executes dropped EXE

    • Loads dropped DLL

    • Unexpected DNS network traffic destination

      Network traffic to other servers than the configured DNS servers was detected on the DNS port.

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

1
T1082

Tasks