General

  • Target

    Freshbuild.exe

  • Size

    415KB

  • MD5

    07101cac5b9477ba636cd8ca7b9932cb

  • SHA1

    59ea7fd9ae6ded8c1b7240a4bf9399b4eb3849f1

  • SHA256

    488385cd54d14790b03fa7c7dc997ebea3f7b2a8499e5927eb437a3791102a77

  • SHA512

    02240ff51a74966bc31cfcc901105096eb871f588efaa9be1a829b4ee6f245bd9dca37be7e2946ba6315feea75c3dce5f490847250e62081445cd25b0f406887

  • SSDEEP

    12288:5fSPtGpmLb84Jjzo6yrBuKuJ+ITOC0Ud:UtGpmf8edykhV0Ud

Score
10/10

Malware Config

Extracted

Family

amadey

Version

4.30

Botnet

4b955f

C2

http://185.172.128.116

Attributes
  • install_dir

    b66a8ae076

  • install_file

    Hkbsse.exe

  • strings_key

    d0f1609e2fff913c5fc0b879a0d56e06

  • url_paths

    /Mb3GvQs8/index.php

rc4.plain

Signatures

  • Amadey family
  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

Files

  • Freshbuild.exe
    .exe windows:6 windows x86 arch:x86

    39e221da42b9cac717741c15ca264eb9


    Headers

    Imports

    Sections