General

  • Target

    aff9ca3cd6ca900ab3dd3ea875f8bca826848a336281890ca5eda5a62e3cb731

  • Size

    163KB

  • Sample

    240704-cvb1qazbkj

  • MD5

    a45e791505ac12f36b1866a176697798

  • SHA1

    2358a5b37c5af2223739dd72b8026d65a3956f4c

  • SHA256

    aff9ca3cd6ca900ab3dd3ea875f8bca826848a336281890ca5eda5a62e3cb731

  • SHA512

    7f23a017125135f8995a16cad7de4a57ddf7ccb7413c7cb3693c2a96a95afa52ece68d93df0fe0d4795ec25e0cc51b13842e9900b73efd2c8c61d76dbea97786

  • SSDEEP

    1536:PfJ7u02SwxvFpxLLSTytE0PqhkJklProNVU4qNVUrk/9QbfBr+7GwKrPAsqNVU:XJ7uH9pcOtlHkltOrWKDBr+yJb

Malware Config

Extracted

Family

gozi

Targets

    • Target

      aff9ca3cd6ca900ab3dd3ea875f8bca826848a336281890ca5eda5a62e3cb731

    • Size

      163KB

    • MD5

      a45e791505ac12f36b1866a176697798

    • SHA1

      2358a5b37c5af2223739dd72b8026d65a3956f4c

    • SHA256

      aff9ca3cd6ca900ab3dd3ea875f8bca826848a336281890ca5eda5a62e3cb731

    • SHA512

      7f23a017125135f8995a16cad7de4a57ddf7ccb7413c7cb3693c2a96a95afa52ece68d93df0fe0d4795ec25e0cc51b13842e9900b73efd2c8c61d76dbea97786

    • SSDEEP

      1536:PfJ7u02SwxvFpxLLSTytE0PqhkJklProNVU4qNVUrk/9QbfBr+7GwKrPAsqNVU:XJ7uH9pcOtlHkltOrWKDBr+yJb

    • Adds autorun key to be loaded by Explorer.exe on startup

    • Gozi

      Gozi is a well-known and widely distributed banking trojan.

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks