General

  • Target

    83a475e89ba47df9bc3b5e27bb3af2928da01fc25a2de4d672db2e61b22d95e8

  • Size

    5.2MB

  • Sample

    240701-fqwq4sxbke

  • MD5

    55db085a5e2ae74fba99159dd4c7d159

  • SHA1

    fd7fc239dc4355c3a15268958c21708f214d1cf2

  • SHA256

    83a475e89ba47df9bc3b5e27bb3af2928da01fc25a2de4d672db2e61b22d95e8

  • SHA512

    689d4811f650ed1bd424851b5a730b91bf8104c75719901f053ea4f7c021538baa05b88a7325a29a6b2ed3bfa405767e30a1b9ca2a8e001b8df5dc646305f1c3

  • SSDEEP

    98304:CACzFqEtInZjnKwc3s+HO3J2cxQal2ANiSx7TWJoDfiQx9W:pkl6y3i3J2cmm2CByobiQa

Malware Config

Targets

    • Target

      83a475e89ba47df9bc3b5e27bb3af2928da01fc25a2de4d672db2e61b22d95e8

    • Size

      5.2MB

    • MD5

      55db085a5e2ae74fba99159dd4c7d159

    • SHA1

      fd7fc239dc4355c3a15268958c21708f214d1cf2

    • SHA256

      83a475e89ba47df9bc3b5e27bb3af2928da01fc25a2de4d672db2e61b22d95e8

    • SHA512

      689d4811f650ed1bd424851b5a730b91bf8104c75719901f053ea4f7c021538baa05b88a7325a29a6b2ed3bfa405767e30a1b9ca2a8e001b8df5dc646305f1c3

    • SSDEEP

      98304:CACzFqEtInZjnKwc3s+HO3J2cxQal2ANiSx7TWJoDfiQx9W:pkl6y3i3J2cmm2CByobiQa

    • Detect Socks5Systemz Payload

    • Socks5Systemz

      Socks5Systemz is a botnet written in C++.

    • Executes dropped EXE

    • Loads dropped DLL

    • Unexpected DNS network traffic destination

      Network traffic to other servers than the configured DNS servers was detected on the DNS port.

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

1
T1082

Tasks