General

  • Target

    2e25b2f69299c7392ed359c85177ceb579abb7c72714de81fb070fdba5f109be

  • Size

    5.2MB

  • Sample

    240703-fmkjnsycpa

  • MD5

    54726c623f49a391b3d773638c9817e7

  • SHA1

    bd713562360153fd816ef2bcbedd895499f6740c

  • SHA256

    2e25b2f69299c7392ed359c85177ceb579abb7c72714de81fb070fdba5f109be

  • SHA512

    5542a9904381c33925a21d6ef4e53c85e9867b4ba3e2be99bb3a048c207a6be4ab3566a7d4f13f343f1c10a6b12ceb50de055f9752bcb9708fe861fb0bb2e29d

  • SSDEEP

    98304:CrgSF3k6HKqh5wgBC+9Dxz/94h3MP3VTgi/W8SIw4iJXnC6gWqAqbLHdoQxDa:QKq/BXJFZ3dgudSIpubgWnqbeQpa

Malware Config

Targets

    • Target

      2e25b2f69299c7392ed359c85177ceb579abb7c72714de81fb070fdba5f109be

    • Size

      5.2MB

    • MD5

      54726c623f49a391b3d773638c9817e7

    • SHA1

      bd713562360153fd816ef2bcbedd895499f6740c

    • SHA256

      2e25b2f69299c7392ed359c85177ceb579abb7c72714de81fb070fdba5f109be

    • SHA512

      5542a9904381c33925a21d6ef4e53c85e9867b4ba3e2be99bb3a048c207a6be4ab3566a7d4f13f343f1c10a6b12ceb50de055f9752bcb9708fe861fb0bb2e29d

    • SSDEEP

      98304:CrgSF3k6HKqh5wgBC+9Dxz/94h3MP3VTgi/W8SIw4iJXnC6gWqAqbLHdoQxDa:QKq/BXJFZ3dgudSIpubgWnqbeQpa

    • Detect Socks5Systemz Payload

    • Socks5Systemz

      Socks5Systemz is a botnet written in C++.

    • Executes dropped EXE

    • Loads dropped DLL

    • Unexpected DNS network traffic destination

      Network traffic to other servers than the configured DNS servers was detected on the DNS port.

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

1
T1082

Tasks