General

  • Target

    8563d0a0e525fb28bcc7f37b381ee508cb4227336b2949eb9fd6b97ffe29d6cd

  • Size

    163KB

  • Sample

    240702-aaaaaa1hkn

  • MD5

    be9f2576b9418f8991da0e16b7c2c8b0

  • SHA1

    8473021121bf6c86529c8b11f9a7d78d6fe877f6

  • SHA256

    8563d0a0e525fb28bcc7f37b381ee508cb4227336b2949eb9fd6b97ffe29d6cd

  • SHA512

    948cab0786960ac551f8d4ac28d656765bf08a9b6323bd4795c59cd8068710a09c24dc905e9de4ee0905ecbbcb725349d7b2ac621fece4bbe33e49115d889cd4

  • SSDEEP

    3072:xDlG8Sgsz1xJCKxCoxKsaltOrWKDBr+yJb:tE8SLJCKxvxTaLOf

Malware Config

Extracted

Family

gozi

Targets

    • Target

      8563d0a0e525fb28bcc7f37b381ee508cb4227336b2949eb9fd6b97ffe29d6cd

    • Size

      163KB

    • MD5

      be9f2576b9418f8991da0e16b7c2c8b0

    • SHA1

      8473021121bf6c86529c8b11f9a7d78d6fe877f6

    • SHA256

      8563d0a0e525fb28bcc7f37b381ee508cb4227336b2949eb9fd6b97ffe29d6cd

    • SHA512

      948cab0786960ac551f8d4ac28d656765bf08a9b6323bd4795c59cd8068710a09c24dc905e9de4ee0905ecbbcb725349d7b2ac621fece4bbe33e49115d889cd4

    • SSDEEP

      3072:xDlG8Sgsz1xJCKxCoxKsaltOrWKDBr+yJb:tE8SLJCKxvxTaLOf

    • Adds autorun key to be loaded by Explorer.exe on startup

    • Gozi

      Gozi is a well-known and widely distributed banking trojan.

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks