Resubmissions

02-07-2024 20:30

240702-y99q7axgja 10

02-07-2024 20:21

240702-y449hsxdja 10

15-06-2024 12:25

240615-plyjksthpp 10

General

  • Target

    25fc6bc420b8a78e3d6b8faf4bbf0e50dc5f152842e43663fa89f35e2faf8587.exe

  • Size

    9.9MB

  • Sample

    240702-y99q7axgja

  • MD5

    36738debf327efec480324af18b94766

  • SHA1

    5485d691b89a483f823a5be4b3c2b9a3a755f3fd

  • SHA256

    25fc6bc420b8a78e3d6b8faf4bbf0e50dc5f152842e43663fa89f35e2faf8587

  • SHA512

    d58b10fcd8cf88cda44e9fd1bd7a7d5c029ccf920464290152c9f005382b3720b6a84ef1750a4595c4611905cc22f358daa0fb5a2e7de4ee51be1907c6c3c64e

  • SSDEEP

    196608:JkSJiPMvxwqNSb4OFVT20XYwO63UwxtQLODByENIUMTnh:OQmkwqNSb4OFV2ZwOnwxtsqNTqnh

Score
10/10

Malware Config

Extracted

Family

amadey

Version

4.30

Botnet

237e24

C2

http://77.91.77.140

Attributes
  • install_dir

    128c262c3e

  • install_file

    Hkbsse.exe

  • strings_key

    290b81e8c919db72c216d14cb1d817dd

  • url_paths

    /g9bkfkWf/index.php

rc4.plain

Targets

    • Target

      25fc6bc420b8a78e3d6b8faf4bbf0e50dc5f152842e43663fa89f35e2faf8587.exe

    • Size

      9.9MB

    • MD5

      36738debf327efec480324af18b94766

    • SHA1

      5485d691b89a483f823a5be4b3c2b9a3a755f3fd

    • SHA256

      25fc6bc420b8a78e3d6b8faf4bbf0e50dc5f152842e43663fa89f35e2faf8587

    • SHA512

      d58b10fcd8cf88cda44e9fd1bd7a7d5c029ccf920464290152c9f005382b3720b6a84ef1750a4595c4611905cc22f358daa0fb5a2e7de4ee51be1907c6c3c64e

    • SSDEEP

      196608:JkSJiPMvxwqNSb4OFVT20XYwO63UwxtQLODByENIUMTnh:OQmkwqNSb4OFV2ZwOnwxtsqNTqnh

    Score
    10/10
    • Amadey

      Amadey bot is a simple trojan bot primarily used for collecting reconnaissance information.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks