Behavioral task
behavioral1
Sample
4516-91-0x0000000000850000-0x0000000000CFF000-memory.exe
Resource
win7-20240508-en
Behavioral task
behavioral2
Sample
4516-91-0x0000000000850000-0x0000000000CFF000-memory.exe
Resource
win10v2004-20240508-en
General
-
Target
4516-91-0x0000000000850000-0x0000000000CFF000-memory.dmp
-
Size
4.7MB
-
MD5
4a1c101a6de132573c870b5a8f0e3d7e
-
SHA1
264355694e61243f9504a95316e43dd8ccb8c8e4
-
SHA256
299f32ea76607477ed23ec25878098bebc0a64f11da0c685e8fd91bb1dd4742a
-
SHA512
94aa1ec4345329092c7bddcc134c589cc9a253396a3c02956865c20e1ccb1a4b580fd13d8948a6933fa2fc1ac9461b4eb5b63ee9e696320837c87f72978bfb29
-
SSDEEP
98304:7SM1Cbf+LjWzYrDhZxCyXTFC53AloglF/xu6ir9W6AAmWq4fXczoVgyGD96diUgV:7SCp9a8fscFbWU
Malware Config
Extracted
amadey
4.30
4dd39d
http://77.91.77.82
-
install_dir
ad40971b6b
-
install_file
explorti.exe
-
strings_key
a434973ad22def7137dbb5e059b7081e
-
url_paths
/Hun4Ko/index.php
Signatures
-
Amadey family
-
Unsigned PE 1 IoCs
Checks for missing Authenticode signature.
Processes:
resource 4516-91-0x0000000000850000-0x0000000000CFF000-memory.dmp
Files
-
4516-91-0x0000000000850000-0x0000000000CFF000-memory.dmp.exe windows:6 windows x86 arch:x86
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_32BIT_MACHINE
Sections
Size: 183KB - Virtual size: 416KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rsrc Size: 512B - Virtual size: 480B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.idata Size: 512B - Virtual size: 4KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Size: 512B - Virtual size: 2.6MB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
fviyvaow Size: 1.6MB - Virtual size: 1.6MB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
tkswyxmm Size: 1024B - Virtual size: 4KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.taggant Size: 8KB - Virtual size: 12KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE