General

  • Target

    e8d3a9188843cc7010cb972c4820c2aef404969ca20f6f334a894bb25b73cc1d

  • Size

    5.5MB

  • Sample

    240701-st63ga1hkk

  • MD5

    09f1c567bd19d4164253e742b57e2eb0

  • SHA1

    ed0cc374007a7b1a6ddc29a1b4f93cddae2abce0

  • SHA256

    e8d3a9188843cc7010cb972c4820c2aef404969ca20f6f334a894bb25b73cc1d

  • SHA512

    ca491035ec7e803d4e67d966e3047bcef102c1215568b173ead09a8ee08a2ba466fad0b24b29fdee0a2d9b4c9520f08996f8da6e2bdbbfdc49156926d8ed67a1

  • SSDEEP

    98304:C3vvG3Y3pEihsWSZ8w197R3GeAaU/QjOAqCf2EcwzwckD1R/aAiTaQx7:YvvP3cp19F3QClnOpWo1Ja3TaQV

Malware Config

Targets

    • Target

      e8d3a9188843cc7010cb972c4820c2aef404969ca20f6f334a894bb25b73cc1d

    • Size

      5.5MB

    • MD5

      09f1c567bd19d4164253e742b57e2eb0

    • SHA1

      ed0cc374007a7b1a6ddc29a1b4f93cddae2abce0

    • SHA256

      e8d3a9188843cc7010cb972c4820c2aef404969ca20f6f334a894bb25b73cc1d

    • SHA512

      ca491035ec7e803d4e67d966e3047bcef102c1215568b173ead09a8ee08a2ba466fad0b24b29fdee0a2d9b4c9520f08996f8da6e2bdbbfdc49156926d8ed67a1

    • SSDEEP

      98304:C3vvG3Y3pEihsWSZ8w197R3GeAaU/QjOAqCf2EcwzwckD1R/aAiTaQx7:YvvP3cp19F3QClnOpWo1Ja3TaQV

    • Detect Socks5Systemz Payload

    • Socks5Systemz

      Socks5Systemz is a botnet written in C++.

    • Executes dropped EXE

    • Loads dropped DLL

    • Unexpected DNS network traffic destination

      Network traffic to other servers than the configured DNS servers was detected on the DNS port.

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

1
T1082

Tasks