General

  • Target

    4eff1ef626264e3f1d795dfd71ea0b217810b5902dcb46bf914e9466ba81aeae

  • Size

    5.0MB

  • Sample

    240701-fpw1gszgnq

  • MD5

    0c08920d01eeb7bc6e2c909e750d6183

  • SHA1

    2221bfda019f34b8ad75a24e5d70d70613fe9f7e

  • SHA256

    4eff1ef626264e3f1d795dfd71ea0b217810b5902dcb46bf914e9466ba81aeae

  • SHA512

    b61e6c4bc8474d205a6df9d48e059831947b372ff87c16f950b2d1cfde0102f2815bf61c3b8d1968d632a461d622103098a5760e44e72c0987d84aa208226e26

  • SSDEEP

    98304:CbznFGZc1nc7Qbx59/31/sSZEq1N0D5dwt6ypECFUL9hdqqkQxj:EEMncEbx59f1Eq1qlKpEQyvhkQ9

Malware Config

Targets

    • Target

      4eff1ef626264e3f1d795dfd71ea0b217810b5902dcb46bf914e9466ba81aeae

    • Size

      5.0MB

    • MD5

      0c08920d01eeb7bc6e2c909e750d6183

    • SHA1

      2221bfda019f34b8ad75a24e5d70d70613fe9f7e

    • SHA256

      4eff1ef626264e3f1d795dfd71ea0b217810b5902dcb46bf914e9466ba81aeae

    • SHA512

      b61e6c4bc8474d205a6df9d48e059831947b372ff87c16f950b2d1cfde0102f2815bf61c3b8d1968d632a461d622103098a5760e44e72c0987d84aa208226e26

    • SSDEEP

      98304:CbznFGZc1nc7Qbx59/31/sSZEq1N0D5dwt6ypECFUL9hdqqkQxj:EEMncEbx59f1Eq1qlKpEQyvhkQ9

    • Detect Socks5Systemz Payload

    • Socks5Systemz

      Socks5Systemz is a botnet written in C++.

    • Executes dropped EXE

    • Loads dropped DLL

    • Unexpected DNS network traffic destination

      Network traffic to other servers than the configured DNS servers was detected on the DNS port.

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

1
T1082

Tasks