General

  • Target

    c74a9b54c4bc140809015d38271c8dab81eb01d759f26ae522e6688bacad78a4

  • Size

    5.3MB

  • Sample

    240703-aaf3tswhja

  • MD5

    561b311d83ba4bc0de858af0c5b50151

  • SHA1

    aa7697d0b5fbcafc46a24347ea044061ebf31f69

  • SHA256

    c74a9b54c4bc140809015d38271c8dab81eb01d759f26ae522e6688bacad78a4

  • SHA512

    b54f920cbe92c961907357ed69f9f168e81ed84231056ff965203a3ce6f0881f4966077a40798180e21d1ac4be4b4ff5ec5e4b78ead127f9a2136769bfbb062b

  • SSDEEP

    98304:CXXPL2dEa4klx8+QonBn5FwY8zzOwGTl1YKa23syb/n9svUUkHVagzQxla:qPAEa4A8+QOn51CGTPScPm/ezQva

Malware Config

Targets

    • Target

      c74a9b54c4bc140809015d38271c8dab81eb01d759f26ae522e6688bacad78a4

    • Size

      5.3MB

    • MD5

      561b311d83ba4bc0de858af0c5b50151

    • SHA1

      aa7697d0b5fbcafc46a24347ea044061ebf31f69

    • SHA256

      c74a9b54c4bc140809015d38271c8dab81eb01d759f26ae522e6688bacad78a4

    • SHA512

      b54f920cbe92c961907357ed69f9f168e81ed84231056ff965203a3ce6f0881f4966077a40798180e21d1ac4be4b4ff5ec5e4b78ead127f9a2136769bfbb062b

    • SSDEEP

      98304:CXXPL2dEa4klx8+QonBn5FwY8zzOwGTl1YKa23syb/n9svUUkHVagzQxla:qPAEa4A8+QOn51CGTPScPm/ezQva

    • Detect Socks5Systemz Payload

    • Socks5Systemz

      Socks5Systemz is a botnet written in C++.

    • Executes dropped EXE

    • Loads dropped DLL

    • Unexpected DNS network traffic destination

      Network traffic to other servers than the configured DNS servers was detected on the DNS port.

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

1
T1082

Tasks