General

  • Target

    4516-91-0x0000000000850000-0x0000000000CFF000-memory.dmp

  • Size

    4.7MB

  • Sample

    240630-bnfjwsvdnk

  • MD5

    4a1c101a6de132573c870b5a8f0e3d7e

  • SHA1

    264355694e61243f9504a95316e43dd8ccb8c8e4

  • SHA256

    299f32ea76607477ed23ec25878098bebc0a64f11da0c685e8fd91bb1dd4742a

  • SHA512

    94aa1ec4345329092c7bddcc134c589cc9a253396a3c02956865c20e1ccb1a4b580fd13d8948a6933fa2fc1ac9461b4eb5b63ee9e696320837c87f72978bfb29

  • SSDEEP

    98304:7SM1Cbf+LjWzYrDhZxCyXTFC53AloglF/xu6ir9W6AAmWq4fXczoVgyGD96diUgV:7SCp9a8fscFbWU

Score
10/10

Malware Config

Extracted

Family

amadey

Version

4.30

Botnet

4dd39d

C2

http://77.91.77.82

Attributes
  • install_dir

    ad40971b6b

  • install_file

    explorti.exe

  • strings_key

    a434973ad22def7137dbb5e059b7081e

  • url_paths

    /Hun4Ko/index.php

rc4.plain

Targets

    • Target

      4516-91-0x0000000000850000-0x0000000000CFF000-memory.dmp

    • Size

      4.7MB

    • MD5

      4a1c101a6de132573c870b5a8f0e3d7e

    • SHA1

      264355694e61243f9504a95316e43dd8ccb8c8e4

    • SHA256

      299f32ea76607477ed23ec25878098bebc0a64f11da0c685e8fd91bb1dd4742a

    • SHA512

      94aa1ec4345329092c7bddcc134c589cc9a253396a3c02956865c20e1ccb1a4b580fd13d8948a6933fa2fc1ac9461b4eb5b63ee9e696320837c87f72978bfb29

    • SSDEEP

      98304:7SM1Cbf+LjWzYrDhZxCyXTFC53AloglF/xu6ir9W6AAmWq4fXczoVgyGD96diUgV:7SCp9a8fscFbWU

    Score
    10/10
    • Amadey

      Amadey bot is a simple trojan bot primarily used for collecting reconnaissance information.

MITRE ATT&CK Matrix

Tasks