General

  • Target

    7774328c1fee5940ae512cfae22164c84b8f564162965b04012bdb4d604cec9b

  • Size

    5.2MB

  • Sample

    240703-nzh6da1gqc

  • MD5

    5f1152855cd1e1edcfb7ef810a399d30

  • SHA1

    77063956b8b24fc5712e24bae39a1090d8eb2389

  • SHA256

    7774328c1fee5940ae512cfae22164c84b8f564162965b04012bdb4d604cec9b

  • SHA512

    0c6f6f3e5e730d59f68417d10185f23528858ccea5264805188116d42c1539c806225f9a30e6050aa2f76be4ed5c323ae69ad0a1cb1003430aad68491a8b2238

  • SSDEEP

    98304:ChQBHtWSBrzyc3FN3fQT8HL6ErLuizq2VWscHsyQTJi1tonx07Qxb:t8Shj1N3ME/Vq2VWr7MizonxGQ5

Malware Config

Targets

    • Target

      7774328c1fee5940ae512cfae22164c84b8f564162965b04012bdb4d604cec9b

    • Size

      5.2MB

    • MD5

      5f1152855cd1e1edcfb7ef810a399d30

    • SHA1

      77063956b8b24fc5712e24bae39a1090d8eb2389

    • SHA256

      7774328c1fee5940ae512cfae22164c84b8f564162965b04012bdb4d604cec9b

    • SHA512

      0c6f6f3e5e730d59f68417d10185f23528858ccea5264805188116d42c1539c806225f9a30e6050aa2f76be4ed5c323ae69ad0a1cb1003430aad68491a8b2238

    • SSDEEP

      98304:ChQBHtWSBrzyc3FN3fQT8HL6ErLuizq2VWscHsyQTJi1tonx07Qxb:t8Shj1N3ME/Vq2VWr7MizonxGQ5

    • Detect Socks5Systemz Payload

    • Socks5Systemz

      Socks5Systemz is a botnet written in C++.

    • Executes dropped EXE

    • Loads dropped DLL

    • Unexpected DNS network traffic destination

      Network traffic to other servers than the configured DNS servers was detected on the DNS port.

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

1
T1082

Tasks