General

  • Target

    388356a00ffa9aa655beec68104cf330e97a72be971a1f2932dbd6acdbe70e39

  • Size

    5.2MB

  • Sample

    240702-t5p4rswaqq

  • MD5

    6c4dbe7bb64e09d17061d2bf0dd5b846

  • SHA1

    7f3332131de057503432e957cdb7336766678b1f

  • SHA256

    388356a00ffa9aa655beec68104cf330e97a72be971a1f2932dbd6acdbe70e39

  • SHA512

    4fd409ccf59f121e594b24de1c57b3102cc6d207b7feee32207f1de90a4c8e15e41485476794faa58348af41355d02ce7dabf1a22c11454c274765ff937d2fbd

  • SSDEEP

    98304:CfJ1K3exMHTe5FsipYXCnVIU/EcCgn6TWlsvaowglIRdl4Qxla:SB5iip0U/xxAWyhYdCQva

Malware Config

Targets

    • Target

      388356a00ffa9aa655beec68104cf330e97a72be971a1f2932dbd6acdbe70e39

    • Size

      5.2MB

    • MD5

      6c4dbe7bb64e09d17061d2bf0dd5b846

    • SHA1

      7f3332131de057503432e957cdb7336766678b1f

    • SHA256

      388356a00ffa9aa655beec68104cf330e97a72be971a1f2932dbd6acdbe70e39

    • SHA512

      4fd409ccf59f121e594b24de1c57b3102cc6d207b7feee32207f1de90a4c8e15e41485476794faa58348af41355d02ce7dabf1a22c11454c274765ff937d2fbd

    • SSDEEP

      98304:CfJ1K3exMHTe5FsipYXCnVIU/EcCgn6TWlsvaowglIRdl4Qxla:SB5iip0U/xxAWyhYdCQva

    • Detect Socks5Systemz Payload

    • Socks5Systemz

      Socks5Systemz is a botnet written in C++.

    • Executes dropped EXE

    • Loads dropped DLL

    • Unexpected DNS network traffic destination

      Network traffic to other servers than the configured DNS servers was detected on the DNS port.

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

1
T1082

Tasks