General

  • Target

    4003b867f19c7eabcf2472b65564c21417de2dd2a418f839f82d0736ae333403.exe

  • Size

    163KB

  • Sample

    240703-grw9pszhqg

  • MD5

    2b9e4f32a763cfe7f22b89e02d38bb50

  • SHA1

    934085001e51f5302f11e245466a60dfcaeff5fb

  • SHA256

    4003b867f19c7eabcf2472b65564c21417de2dd2a418f839f82d0736ae333403

  • SHA512

    3a0398bdc529fea4b5105f16f16f5e2cc87dc6952c768e02831b033ac0ec0003558f430df61adb9aa55099bae4defc6c178cf750f0759ab39c92e2a16cda4c7a

  • SSDEEP

    1536:PdicyfI/+iF5lJMWlBlAowVBxylProNVU4qNVUrk/9QbfBr+7GwKrPAsqNVU:GI/+iFgBxyltOrWKDBr+yJb

Malware Config

Extracted

Family

gozi

Targets

    • Target

      4003b867f19c7eabcf2472b65564c21417de2dd2a418f839f82d0736ae333403.exe

    • Size

      163KB

    • MD5

      2b9e4f32a763cfe7f22b89e02d38bb50

    • SHA1

      934085001e51f5302f11e245466a60dfcaeff5fb

    • SHA256

      4003b867f19c7eabcf2472b65564c21417de2dd2a418f839f82d0736ae333403

    • SHA512

      3a0398bdc529fea4b5105f16f16f5e2cc87dc6952c768e02831b033ac0ec0003558f430df61adb9aa55099bae4defc6c178cf750f0759ab39c92e2a16cda4c7a

    • SSDEEP

      1536:PdicyfI/+iF5lJMWlBlAowVBxylProNVU4qNVUrk/9QbfBr+7GwKrPAsqNVU:GI/+iFgBxyltOrWKDBr+yJb

    • Adds autorun key to be loaded by Explorer.exe on startup

    • Gozi

      Gozi is a well-known and widely distributed banking trojan.

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks