| File name: | git43.7z |
| Full analysis: | https://app.any.run/tasks/71bb7525-6a91-4548-b2f5-12ef5747f5b8 |
| Verdict: | Malicious activity |
| Threats: | Amadey is a formidable Windows infostealer threat, characterized by its persistence mechanisms, modular design, and ability to execute various malicious tasks. |
| Analysis date: | August 26, 2024, 13:35:03 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-7z-compressed |
| File info: | 7-zip archive data, version 0.4 |
| MD5: | 00D8EC6590E9DFF0D9F5CE7A43B82319 |
| SHA1: | 5DD1F7634970467AC5C83B126918FF90FF012B68 |
| SHA256: | 4FD8FBEEEE110A1CE9A669E05D7B81B95A2F393D2EB3373E31FEB5C5E6C8F6BA |
| SSDEEP: | 98304:OXJJlFnvaesw0YK7+usfq4YPiwnBZgFBWIrGRpSVAiJI9NBeUm7j5aykfVWLJv8Q:zkxIpixWrKV5t5 |
| .7z | | | 7-Zip compressed archive (v0.4) (57.1) |
|---|---|---|
| .7z | | | 7-Zip compressed archive (gen) (42.8) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 400 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | powercfg.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) | |||||||||||||||
| 460 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=6352 -childID 6 -isForBrowser -prefsHandle 6360 -prefMapHandle 4704 -prefsLen 36339 -prefMapSize 244343 -jsInitHandle 1444 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {635cd571-1871-4eb5-9093-a0afe95b8aab} 2892 "\\.\pipe\gecko-crash-server-pipe.2892" 1bb91d0c150 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 123.0 | |||||||||||||||
| 884 | "C:\Users\admin\AppData\Local\Temp\0e8d0864aa\svoutse.exe" | C:\Users\admin\AppData\Local\Temp\0e8d0864aa\svoutse.exe | svchost.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 888 | C:\Users\admin\Documents\piratemamm\rws0TNSokwjNPSp83BN_89eX.exe | C:\Users\admin\Documents\piratemamm\rws0TNSokwjNPSp83BN_89eX.exe | RegAsm.exe | ||||||||||||
User: admin Company: Google Chrome Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 127,0,6533,89 Modules
| |||||||||||||||
| 1076 | "C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | — | FileApp.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft .NET Assembly Registration Utility Exit code: 241 Version: 4.8.9037.0 built by: NET481REL1 Modules
| |||||||||||||||
| 1084 | schtasks /create /f /RU "admin" /tr "C:\ProgramData\jewkkwnf\jewkkwnf.exe" /tn "jewkkwnf LG" /sc ONLOGON /rl HIGHEST | C:\Windows\SysWOW64\schtasks.exe | — | PAHqiMJ6oS3x3G0vh_1uPgDK.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Task Scheduler Configuration Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1108 | C:\Users\admin\Documents\piratemamm\4qoOfyuxVT1_zpwUwAZdhwjR.exe | C:\Users\admin\Documents\piratemamm\4qoOfyuxVT1_zpwUwAZdhwjR.exe | — | RegAsm.exe | |||||||||||
User: admin Company: Grounder Outsiders Integrity Level: MEDIUM Description: Deliberates Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 1164 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | powercfg.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) | |||||||||||||||
| 1184 | "C:\Users\admin\Documents\piratemamm\PAHqiMJ6oS3x3G0vh_1uPgDK.exe" | C:\Users\admin\Documents\piratemamm\PAHqiMJ6oS3x3G0vh_1uPgDK.exe | PAHqiMJ6oS3x3G0vh_1uPgDK.exe | ||||||||||||
User: admin Company: Hr9NiFu08oD2 Integrity Level: HIGH Description: botsoft Version: 4.8.3.9 Modules
| |||||||||||||||
| 1280 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | schtasks.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (3964) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3964) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3964) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface |
| Operation: | write | Name: | ShowPassword |
Value: 0 | |||
| (PID) Process: | (3964) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip | |||
| (PID) Process: | (3964) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\git43.7z | |||
| (PID) Process: | (3964) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3964) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3964) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3964) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3964) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3964 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3964.13788\FileApp.exe | — | |
MD5:— | SHA256:— | |||
| 3964 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3964.13788\res\ieframe.dll | executable | |
MD5:7BD6B1BF96E00328B37FBCB6F26DEEF5 | SHA256:39AFC9B9037EBA4CFA93555457D9A23FC58EAFC1CFC4526DE312983D9E6BB6B6 | |||
| 3964 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3964.13788\res\wpnapps.dll | executable | |
MD5:BACCB252E32CDEEE2FCC6AB5E53C6958 | SHA256:AA7F5F06AE9EDF9EC9E6888B749FDC0D7D89E93276B38C17D61BE99FF13296D3 | |||
| 5888 | RegAsm.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\4D1ED785E3365DE6C966A82E99CCE8EA_4FF21E9CE9761A304E66D2F0263F90A7 | binary | |
MD5:4AFD3374AAD3426A763C827DDD2D10EB | SHA256:F469C6A846A71227D876FE87A6752AF919BBE5ABDCBA5BA93E8BE6146B732CBD | |||
| 5888 | RegAsm.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\D03E46CD585BBE111C712E6577BC5F07_56B2A1FF8D0F5C5B4060FCF88A1654FE | der | |
MD5:4B8F9FAF6B12157BEE7E09416E454989 | SHA256:B29D4666C41C14E078D6124E37401ED623D205D4606A39F03E2D07DA585D4710 | |||
| 3964 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3964.13788\res\Windows.UI.Xaml.dll | executable | |
MD5:4F0CE7CE6048E2960488E76F769D3951 | SHA256:A8AD5CC012D34CEF685702DF55CAAAD6ACF62FD8BDF3B5DBEE08E953AB06E555 | |||
| 3964 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3964.13788\res\msftedit.dll | executable | |
MD5:EFE46DD05894C29AD810F5791FB25BA8 | SHA256:7138AE5B4DD7A93E6E06348FB60E3D7DE8C0C31AEA6336CBA3057DFF1D32954E | |||
| 5888 | RegAsm.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\4D1ED785E3365DE6C966A82E99CCE8EA_4FF21E9CE9761A304E66D2F0263F90A7 | der | |
MD5:5AF9B50077844DB9354A0AADCF20153E | SHA256:6287635A639BC479F6B5383BF35E61253885380C7F0E7CE44258772DD91D0CDA | |||
| 5888 | RegAsm.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\EDC238BFF48A31D55A97E1E93892934B_C31B2498754E340573F1336DE607D619 | der | |
MD5:E8438AD135C5D695EA693E288F20A295 | SHA256:867F42C13F30EDEDB6E66F4A4A4EBA0D2179E200BA3187ACAA8C50FE5E45C8F7 | |||
| 5888 | RegAsm.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\EDC238BFF48A31D55A97E1E93892934B_C31B2498754E340573F1336DE607D619 | binary | |
MD5:741DBAAB682735DBC35D08AACF836328 | SHA256:3316FCDF6BBF3F12955472C8F02931FB8CB50F6074697EFE140144C9F8E0D4E5 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6416 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | US | binary | 471 b | whitelisted |
7008 | SIHClient.exe | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | DE | binary | 407 b | whitelisted |
5888 | RegAsm.exe | GET | 200 | 45.91.200.135:80 | http://45.91.200.135/api/crazyfish.php | NL | text | 6 b | unknown |
5888 | RegAsm.exe | POST | 200 | 45.91.200.135:80 | http://45.91.200.135/api/twofish.php | NL | text | 108 b | unknown |
5888 | RegAsm.exe | POST | 200 | 45.91.200.135:80 | http://45.91.200.135/api/twofish.php | NL | text | 2.36 Kb | unknown |
5888 | RegAsm.exe | HEAD | 200 | 147.45.44.104:80 | http://147.45.44.104/revada/66c6fcb30b9dd_123p.exe | RU | — | — | suspicious |
5888 | RegAsm.exe | HEAD | 200 | 147.45.44.104:80 | http://147.45.44.104/prog/66c6def3f0546_sss.exe | RU | — | — | suspicious |
5888 | RegAsm.exe | HEAD | 200 | 147.45.44.104:80 | http://147.45.44.104/malesa/66cb89fccdd00_crypted.exe#1 | RU | — | — | suspicious |
5888 | RegAsm.exe | HEAD | 200 | 147.45.44.104:80 | http://147.45.44.104/yuop/66c8bcf897a73_xin.exe | RU | — | — | suspicious |
5888 | RegAsm.exe | HEAD | 200 | 176.113.115.33:80 | http://176.113.115.33/ssl/install.exe | RU | — | — | suspicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2400 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1356 | RUXIMICS.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2120 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2400 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3260 | svchost.exe | 20.7.1.246:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
2120 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6416 | svchost.exe | 20.190.160.20:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6416 | svchost.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
api.myip.com |
| whitelisted |
ipinfo.io |
| shared |
PID | Process | Class | Message |
|---|---|---|---|
5888 | RegAsm.exe | A Network Trojan was detected | ET MALWARE PrivateLoader CnC Activity (GET) |
5888 | RegAsm.exe | Device Retrieving External IP Address Detected | ET INFO Observed External IP Lookup Domain in TLS SNI (api .myip .com) |
2256 | svchost.exe | Device Retrieving External IP Address Detected | ET INFO External IP Lookup Domain in DNS Lookup (ipinfo .io) |
5888 | RegAsm.exe | Device Retrieving External IP Address Detected | ET POLICY Possible External IP Lookup Domain Observed in SNI (ipinfo. io) |
5888 | RegAsm.exe | Device Retrieving External IP Address Detected | ET POLICY External IP Lookup SSL Cert Observed (ipinfo .io) |
5888 | RegAsm.exe | A Network Trojan was detected | ET MALWARE PrivateLoader CnC Activity (POST) |
5888 | RegAsm.exe | A Network Trojan was detected | LOADER [ANY.RUN] PrivateLoader Check-in |
5888 | RegAsm.exe | Potentially Bad Traffic | ET INFO Executable Download from dotted-quad Host |
5888 | RegAsm.exe | Potentially Bad Traffic | ET INFO Executable Download from dotted-quad Host |
5888 | RegAsm.exe | A Network Trojan was detected | LOADER [ANY.RUN] PrivateLoader Check-in |
Process | Message |
|---|---|
MsykBo4R8r9XRCz81j9axePL.exe |
%s------------------------------------------------
--- Themida Professional ---
--- (c)2012 Oreans Technologies ---
------------------------------------------------
|
aL4kliHT_vaezzWcvD1vTCD3.exe |
%s------------------------------------------------
--- Themida Professional ---
--- (c)2012 Oreans Technologies ---
------------------------------------------------
|
svoutse.exe |
%s------------------------------------------------
--- Themida Professional ---
--- (c)2012 Oreans Technologies ---
------------------------------------------------
|
svoutse.exe |
%s------------------------------------------------
--- Themida Professional ---
--- (c)2012 Oreans Technologies ---
------------------------------------------------
|
svoutse.exe |
%s------------------------------------------------
--- Themida Professional ---
--- (c)2012 Oreans Technologies ---
------------------------------------------------
|
sQ6cpTR0KquisCJl0JME5FqZ.exe |
%s------------------------------------------------
--- Themida Professional ---
--- (c)2012 Oreans Technologies ---
------------------------------------------------
|
dJh8Lahn7QmQTqnZ0Vw8tx7W.exe |
%s------------------------------------------------
--- Themida Professional ---
--- (c)2012 Oreans Technologies ---
------------------------------------------------
|