General

  • Target

    4772-3-0x00000000006D0000-0x0000000000B89000-memory.dmp

  • Size

    4.7MB

  • Sample

    240701-x2pklsvdlc

  • MD5

    a7f033197d99c4fdd6b0d08d52e1bdd5

  • SHA1

    c78a801d3bdb848734af61b8f00bf49233d02c45

  • SHA256

    efea96724ccadeabf0f64c9a5ca43f66d61c02aa754ffed7207113b664c6313d

  • SHA512

    27656df574687171bf910a165341ad0c5090c9923744f001fff85cff0c9302ee535e6d8cc272613dc8f72876dc9ae2e940b7953d1d8f075ac2b486d09e031f24

  • SSDEEP

    98304:TaIjzmlqMiXxNG0oL35TE371ld5kdJXjigOdItfQIqi:Ti5K1lLuZzOdIZT

Score
10/10

Malware Config

Extracted

Family

amadey

Version

4.30

Botnet

4dd39d

C2

http://77.91.77.82

Attributes
  • install_dir

    ad40971b6b

  • install_file

    explorti.exe

  • strings_key

    a434973ad22def7137dbb5e059b7081e

  • url_paths

    /Hun4Ko/index.php

rc4.plain

Targets

    • Target

      4772-3-0x00000000006D0000-0x0000000000B89000-memory.dmp

    • Size

      4.7MB

    • MD5

      a7f033197d99c4fdd6b0d08d52e1bdd5

    • SHA1

      c78a801d3bdb848734af61b8f00bf49233d02c45

    • SHA256

      efea96724ccadeabf0f64c9a5ca43f66d61c02aa754ffed7207113b664c6313d

    • SHA512

      27656df574687171bf910a165341ad0c5090c9923744f001fff85cff0c9302ee535e6d8cc272613dc8f72876dc9ae2e940b7953d1d8f075ac2b486d09e031f24

    • SSDEEP

      98304:TaIjzmlqMiXxNG0oL35TE371ld5kdJXjigOdItfQIqi:Ti5K1lLuZzOdIZT

    Score
    10/10
    • Amadey

      Amadey bot is a simple trojan bot primarily used for collecting reconnaissance information.

MITRE ATT&CK Matrix

Tasks