General

  • Target

    54766a09fdbf6fe7bd46a98a8d9bd28fab9ce6596dbe98628fab27a561d0b1d8

  • Size

    5.2MB

  • Sample

    240702-v97eaaxhpl

  • MD5

    5888657e5a6e61f8d728a4d548cf68f4

  • SHA1

    77e1ebf70359ad0afd0413dee6aa4cc8e98afbc1

  • SHA256

    54766a09fdbf6fe7bd46a98a8d9bd28fab9ce6596dbe98628fab27a561d0b1d8

  • SHA512

    67380f66cbd3aea60a657685d207a37e1be221495c5fb74d227777d0c67a6f9a8de26cf8711c3e4b02aba9f52563cca45d64bb8ff9502862df424d1c01a2faa0

  • SSDEEP

    98304:Cj2yMhvZMh1Hwl9PJ+o05pLTHzLHEKJrYDmZ82daseu8rq+XFV9/1Qxla:k2yKObwl9NezLRpYDmZBVe7rFH1Qva

Malware Config

Targets

    • Target

      54766a09fdbf6fe7bd46a98a8d9bd28fab9ce6596dbe98628fab27a561d0b1d8

    • Size

      5.2MB

    • MD5

      5888657e5a6e61f8d728a4d548cf68f4

    • SHA1

      77e1ebf70359ad0afd0413dee6aa4cc8e98afbc1

    • SHA256

      54766a09fdbf6fe7bd46a98a8d9bd28fab9ce6596dbe98628fab27a561d0b1d8

    • SHA512

      67380f66cbd3aea60a657685d207a37e1be221495c5fb74d227777d0c67a6f9a8de26cf8711c3e4b02aba9f52563cca45d64bb8ff9502862df424d1c01a2faa0

    • SSDEEP

      98304:Cj2yMhvZMh1Hwl9PJ+o05pLTHzLHEKJrYDmZ82daseu8rq+XFV9/1Qxla:k2yKObwl9NezLRpYDmZBVe7rFH1Qva

    • Detect Socks5Systemz Payload

    • Socks5Systemz

      Socks5Systemz is a botnet written in C++.

    • Executes dropped EXE

    • Loads dropped DLL

    • Unexpected DNS network traffic destination

      Network traffic to other servers than the configured DNS servers was detected on the DNS port.

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

1
T1082

Tasks