General

  • Target

    013d13f8c55fb6aab6a5ab130d3d7c5939ba643cab40f6a08f60e32c6eeabc5c

  • Size

    5.1MB

  • Sample

    240703-jf9f1axanm

  • MD5

    6e1794bc4c96b2f5e042846b4c4e28fa

  • SHA1

    feae443c065b2de10253514a3b9adbac6734f7cd

  • SHA256

    013d13f8c55fb6aab6a5ab130d3d7c5939ba643cab40f6a08f60e32c6eeabc5c

  • SHA512

    2fc830b56513df52eaa0ca0379edd69b3fe5708875195fee82f9cc76b59c6b7c323778e784658e67017716fb408df685985b4f511c3ca3d207367c21afe77aad

  • SSDEEP

    98304:Cho9J4KkfFNIfi/e1lX0JOA4GPXIj7awG/NNYVkwnKirPeOq3c5QxDa:7Jk4fae1IOdGPsWYVnKircc5Qpa

Malware Config

Targets

    • Target

      013d13f8c55fb6aab6a5ab130d3d7c5939ba643cab40f6a08f60e32c6eeabc5c

    • Size

      5.1MB

    • MD5

      6e1794bc4c96b2f5e042846b4c4e28fa

    • SHA1

      feae443c065b2de10253514a3b9adbac6734f7cd

    • SHA256

      013d13f8c55fb6aab6a5ab130d3d7c5939ba643cab40f6a08f60e32c6eeabc5c

    • SHA512

      2fc830b56513df52eaa0ca0379edd69b3fe5708875195fee82f9cc76b59c6b7c323778e784658e67017716fb408df685985b4f511c3ca3d207367c21afe77aad

    • SSDEEP

      98304:Cho9J4KkfFNIfi/e1lX0JOA4GPXIj7awG/NNYVkwnKirPeOq3c5QxDa:7Jk4fae1IOdGPsWYVnKircc5Qpa

    • Detect Socks5Systemz Payload

    • Socks5Systemz

      Socks5Systemz is a botnet written in C++.

    • Executes dropped EXE

    • Loads dropped DLL

    • Unexpected DNS network traffic destination

      Network traffic to other servers than the configured DNS servers was detected on the DNS port.

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

1
T1082

Tasks