Analysis

  • max time kernel
    119s
  • max time network
    121s
  • platform
    windows7_x64
  • resource
    win7-20240220-en
  • resource tags

    arch:x64arch:x86image:win7-20240220-enlocale:en-usos:windows7-x64system
  • submitted
    30-06-2024 16:27

General

  • Target

    2060-3-0x0000000000FD0000-0x000000000148D000-memory.exe

  • Size

    4.7MB

  • MD5

    66aa0c7fb32464254638b655d63e1a42

  • SHA1

    c8706f063005333346d122ba41c60ceeb1e1267a

  • SHA256

    52428ad537a55d3e6b33bca0f8eb559269cb3bb15158da49f345f9a6ed0189a4

  • SHA512

    841e62a753c5d2cab07b642fdcab6a8f4f81f4067aaf88b3962392ae21d46a41805713933c370a716775b0fe1585aab754cfa9605a9bb8b06c3d71a2880b73d8

  • SSDEEP

    98304:r/vM0q7VAf9U9O0q8EXCVIsM9jMs7vRN:r8k3C2NMs7v

Score
10/10

Malware Config

Signatures

  • Amadey

    Amadey bot is a simple trojan bot primarily used for collecting reconnaissance information.

Processes

  • C:\Users\Admin\AppData\Local\Temp\2060-3-0x0000000000FD0000-0x000000000148D000-memory.exe
    "C:\Users\Admin\AppData\Local\Temp\2060-3-0x0000000000FD0000-0x000000000148D000-memory.exe"
    1⤵
      PID:2464

    Network

    MITRE ATT&CK Matrix

    Replay Monitor

    Loading Replay Monitor...

    Downloads

    • memory/2464-0-0x0000000000FD0000-0x000000000148D000-memory.dmp
      Filesize

      4.7MB