General

  • Target

    484785da5e1c9c8927c2b71d9547cac7d8e88e386fb518a9fc41a3abe51b1bbc

  • Size

    5.4MB

  • Sample

    240701-gxqn4s1enn

  • MD5

    9a1a2cdb18b0aaf93a02d07384c034e0

  • SHA1

    3e34b1b0d98e3caa86d8680dcf417595ccdb8ea3

  • SHA256

    484785da5e1c9c8927c2b71d9547cac7d8e88e386fb518a9fc41a3abe51b1bbc

  • SHA512

    0df3523b6c75a8b57e9ad0c756a83331dee7d30cf7df0a5090e533998d7dd67dfe1f76959252eef47716d95376f4b727d8ced2d341278a9c3826221d295edbae

  • SSDEEP

    98304:CrHuP7y7pohnrl/wze0Fs37IgHIWmLEnsPGi6V2SehJkBpTPoytQx2:GLVcoze+DdFpq+ctPoytQw

Malware Config

Targets

    • Target

      484785da5e1c9c8927c2b71d9547cac7d8e88e386fb518a9fc41a3abe51b1bbc

    • Size

      5.4MB

    • MD5

      9a1a2cdb18b0aaf93a02d07384c034e0

    • SHA1

      3e34b1b0d98e3caa86d8680dcf417595ccdb8ea3

    • SHA256

      484785da5e1c9c8927c2b71d9547cac7d8e88e386fb518a9fc41a3abe51b1bbc

    • SHA512

      0df3523b6c75a8b57e9ad0c756a83331dee7d30cf7df0a5090e533998d7dd67dfe1f76959252eef47716d95376f4b727d8ced2d341278a9c3826221d295edbae

    • SSDEEP

      98304:CrHuP7y7pohnrl/wze0Fs37IgHIWmLEnsPGi6V2SehJkBpTPoytQx2:GLVcoze+DdFpq+ctPoytQw

    • Detect Socks5Systemz Payload

    • Socks5Systemz

      Socks5Systemz is a botnet written in C++.

    • Executes dropped EXE

    • Loads dropped DLL

    • Unexpected DNS network traffic destination

      Network traffic to other servers than the configured DNS servers was detected on the DNS port.

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

1
T1082

Tasks