General

  • Target

    4548-95-0x00000000005C0000-0x0000000000A9E000-memory.dmp

  • Size

    4.9MB

  • MD5

    b266cae00e9b5c89572ea05a89e2fcfe

  • SHA1

    62653d30936e76ee4531857cbd0dbc5b50f33bdc

  • SHA256

    67bba79ee67a317a7f31b70ea34bbf8f356823f0af920f7b523839d56161205a

  • SHA512

    95b6e5a994f895a8e1e4f75edd43ef330f9a5929fe6505d54f84e590a19c16496327f79e2ea9d2eb5c5823ecae630b686e6d6b3634c6980303665aa962ee83cd

  • SSDEEP

    98304:Y9KMefCidSo9fquB/AB1cYQ0oOcXvVhj0/qsDc269ZJP1:Y4CWoB160opr0CmSJP1

Score
10/10

Malware Config

Extracted

Family

amadey

Version

4.30

Botnet

4dd39d

C2

http://77.91.77.82

Attributes
  • install_dir

    ad40971b6b

  • install_file

    explorti.exe

  • strings_key

    a434973ad22def7137dbb5e059b7081e

  • url_paths

    /Hun4Ko/index.php

rc4.plain

Signatures

  • Amadey family
  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

Files

  • 4548-95-0x00000000005C0000-0x0000000000A9E000-memory.dmp
    .exe windows:6 windows x86 arch:x86


    Headers

    Sections