General

  • Target

    dcc918333f3fcee563ed6a38c8204a345c2c417da34bed05e2641cc0d0fb7110

  • Size

    163KB

  • Sample

    240706-d6pxdsxdje

  • MD5

    3cb5e7c5a0af0453d27ef024b73b76fe

  • SHA1

    41deff88c8fdcf211cd5b49039f1a5ca9ca42fb6

  • SHA256

    dcc918333f3fcee563ed6a38c8204a345c2c417da34bed05e2641cc0d0fb7110

  • SHA512

    28359c8228b4d03d40de5daafa83984b7a78cad369a5f4a02049fdbec1e0150e5834177de2249c137c5b6453806888777a295eb1dca24d558a9d754d021408c6

  • SSDEEP

    3072:MA3LRTuDvYLFd1WDpCZqfYao4+mo9ltOrWKDBr+yJb:lRTuDQpHZnvmo9LOf

Malware Config

Extracted

Family

gozi

Targets

    • Target

      dcc918333f3fcee563ed6a38c8204a345c2c417da34bed05e2641cc0d0fb7110

    • Size

      163KB

    • MD5

      3cb5e7c5a0af0453d27ef024b73b76fe

    • SHA1

      41deff88c8fdcf211cd5b49039f1a5ca9ca42fb6

    • SHA256

      dcc918333f3fcee563ed6a38c8204a345c2c417da34bed05e2641cc0d0fb7110

    • SHA512

      28359c8228b4d03d40de5daafa83984b7a78cad369a5f4a02049fdbec1e0150e5834177de2249c137c5b6453806888777a295eb1dca24d558a9d754d021408c6

    • SSDEEP

      3072:MA3LRTuDvYLFd1WDpCZqfYao4+mo9ltOrWKDBr+yJb:lRTuDQpHZnvmo9LOf

    • Adds autorun key to be loaded by Explorer.exe on startup

    • Gozi

      Gozi is a well-known and widely distributed banking trojan.

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks