General

  • Target

    4548-95-0x00000000005C0000-0x0000000000A9E000-memory.dmp

  • Size

    4.9MB

  • Sample

    240629-bwjxaaxfng

  • MD5

    b266cae00e9b5c89572ea05a89e2fcfe

  • SHA1

    62653d30936e76ee4531857cbd0dbc5b50f33bdc

  • SHA256

    67bba79ee67a317a7f31b70ea34bbf8f356823f0af920f7b523839d56161205a

  • SHA512

    95b6e5a994f895a8e1e4f75edd43ef330f9a5929fe6505d54f84e590a19c16496327f79e2ea9d2eb5c5823ecae630b686e6d6b3634c6980303665aa962ee83cd

  • SSDEEP

    98304:Y9KMefCidSo9fquB/AB1cYQ0oOcXvVhj0/qsDc269ZJP1:Y4CWoB160opr0CmSJP1

Score
10/10

Malware Config

Extracted

Family

amadey

Version

4.30

Botnet

4dd39d

C2

http://77.91.77.82

Attributes
  • install_dir

    ad40971b6b

  • install_file

    explorti.exe

  • strings_key

    a434973ad22def7137dbb5e059b7081e

  • url_paths

    /Hun4Ko/index.php

rc4.plain

Targets

    • Target

      4548-95-0x00000000005C0000-0x0000000000A9E000-memory.dmp

    • Size

      4.9MB

    • MD5

      b266cae00e9b5c89572ea05a89e2fcfe

    • SHA1

      62653d30936e76ee4531857cbd0dbc5b50f33bdc

    • SHA256

      67bba79ee67a317a7f31b70ea34bbf8f356823f0af920f7b523839d56161205a

    • SHA512

      95b6e5a994f895a8e1e4f75edd43ef330f9a5929fe6505d54f84e590a19c16496327f79e2ea9d2eb5c5823ecae630b686e6d6b3634c6980303665aa962ee83cd

    • SSDEEP

      98304:Y9KMefCidSo9fquB/AB1cYQ0oOcXvVhj0/qsDc269ZJP1:Y4CWoB160opr0CmSJP1

    Score
    10/10
    • Amadey

      Amadey bot is a simple trojan bot primarily used for collecting reconnaissance information.

MITRE ATT&CK Matrix

Tasks