General

  • Target

    60968a25a725013474a3635146b3fe175793dc368e474a3b214c62d562e941e1

  • Size

    5.1MB

  • Sample

    240702-msjb5aydrf

  • MD5

    492f02162a70dec847c6bfed9d708cb5

  • SHA1

    428678819734a91b7805a79ad4e6c0c8da6d7572

  • SHA256

    60968a25a725013474a3635146b3fe175793dc368e474a3b214c62d562e941e1

  • SHA512

    abe5bae26efbe2b490b14e5478997c2cc3705a6f464e3e84a7a8dda4c6f48f7b148e0309e934d9f982486d70ad2935639f982c0fb49d6026dbcece8979f43b6b

  • SSDEEP

    98304:CcQeewV2lo/sjPYEtNBDbPdJ+vcmpHVmov9eKAGl/XQuzH6Cr/aT9Qx3:JfVzfEtNhVJ+vZoovbAGZXQMaH9Qx

Malware Config

Targets

    • Target

      60968a25a725013474a3635146b3fe175793dc368e474a3b214c62d562e941e1

    • Size

      5.1MB

    • MD5

      492f02162a70dec847c6bfed9d708cb5

    • SHA1

      428678819734a91b7805a79ad4e6c0c8da6d7572

    • SHA256

      60968a25a725013474a3635146b3fe175793dc368e474a3b214c62d562e941e1

    • SHA512

      abe5bae26efbe2b490b14e5478997c2cc3705a6f464e3e84a7a8dda4c6f48f7b148e0309e934d9f982486d70ad2935639f982c0fb49d6026dbcece8979f43b6b

    • SSDEEP

      98304:CcQeewV2lo/sjPYEtNBDbPdJ+vcmpHVmov9eKAGl/XQuzH6Cr/aT9Qx3:JfVzfEtNhVJ+vZoovbAGZXQMaH9Qx

    • Detect Socks5Systemz Payload

    • Socks5Systemz

      Socks5Systemz is a botnet written in C++.

    • Executes dropped EXE

    • Loads dropped DLL

    • Unexpected DNS network traffic destination

      Network traffic to other servers than the configured DNS servers was detected on the DNS port.

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

1
T1082

Tasks