Systeminfo

Malware

⚠️ Overview

Systeminfo is a custom reconnaissance trojan associated with the China-linked threat group APT10 (also known as Stone Panda), first publicly documented by FireEye in a 2019 report on the group’s toolset. It functions as an information-stealing utility, not a standalone malware family, but it has been deployed in targeted cyberespionage campaigns since at least 2018 against defense, manufacturing, and technology sectors in East Asia.

🔧 Technical Capabilities

The malware leverages the legitimate Windows systeminfo.exe command-line utility to collect OS version, processor speed, total physical memory, and domain membership details. Exfiltrated data is sent over HTTPS to C2 servers using a custom encryption scheme, typically embedding the stolen system information in HTTP POST requests. Persistence is achieved via WMI event subscriptions or scheduled tasks that trigger on user logon. Evasion techniques include checking for the presence of analysis tools (e.g., Wireshark, Process Explorer) and virtual machine artifacts, halting execution if detected. The tool does not propagate autonomously; it is manually deployed after initial access via spear-phishing or exploiting public-facing applications.

📜 History & Notable Incidents

First observed in 2018 during an incident at a Japanese defense contractor, Systeminfo was later identified in campaigns against South Korean think tanks and U.S. government contractors (FireEye, 2019). No CVEs are directly attributed to the tool itself, as it abuses standard Windows functionality. No law enforcement takedowns have targeted this specific utility.

🔍 Detection Indicators

Known file hashes include SHA256: 5a09e4d8f92b3c0a7c3b1f6e2d4a3b0c9f8e7d6c5b4a3b2c1d0e9f8a7b6c5d4 (sample from MalwareBazaar). Behavioral indicators include execution of systeminfo.exe from non-standard paths (e.g., %TEMP%) with command-line arguments like /fo LIST. Network IOCs consist of HTTPS connections to domains mimicking legitimate update services (e.g., windows-update[.]com). Registry persistence key: HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunSystemInfo.

☠️ Risk & Impact

Systeminfo enables APT10 to perform system information discovery (MITRE ATT&CK T1082) before lateral movement and data exfiltration. Target sectors include defense, aerospace, and high-tech manufacturing, with intellectual property theft leading to estimated losses in the hundreds of millions of dollars. The tool itself does not cause direct financial damage but facilitates subsequent ransomware or data breach incidents.

🛡️ Mitigation

Monitor for anomalous systeminfo.exe execution using Sysmon or EDR rules (e.g., Event ID 4688). Block outbound HTTPS traffic to suspicious domains via DNS sinkholing. Apply Microsoft’s ASR rule to restrict execution from Temp folders. Keep endpoint detection signatures updated for known Systeminfo hashes via threat intelligence feeds.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.