Skip to content

Malware

Socks5 Systemz

aka ProxyBox

The Socks5 Systemz malware is a proxy botnet distributed via the PrivateLoader and Amadey loaders.

Socks5 Systemz, also known as ProxyBox, is a Windows malware family.

Background

Socks5 Systemz is a proxy botnet spread through the PrivateLoader and Amadey loaders. Operating since at least 2016, it turns infected machines into proxies that are rented out for malicious use at rates between $1 and $140 per day paid in cryptocurrency. To resist takedown and avoid detection, it relies on a domain generation algorithm (DGA). It keeps a foothold through a Windows service called ContentDWSvc and loads itself into memory using a file named previewer.exe. Estimates put the number of infected systems worldwide at around 10,000, with Russia notably excluded.


Source: Malpedia (Fraunhofer FKIE).