| File name: | file.exe |
| Full analysis: | https://app.any.run/tasks/6d21ccb7-e823-4ae3-b105-969163c1728a |
| Verdict: | Malicious activity |
| Threats: | Amadey is a formidable Windows infostealer threat, characterized by its persistence mechanisms, modular design, and ability to execute various malicious tasks. |
| Analysis date: | December 20, 2024, 16:20:04 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections |
| MD5: | 903052DC4EC888F7F5BCEB743304B9A2 |
| SHA1: | 9A915074586344F727528A5FC63B86B6083E291B |
| SHA256: | 94892AE5C3BEE71AD27491E1801B78AF3789A15CACC1817DE0A970854B841587 |
| SSDEEP: | 98304:TFJlXlebgxnkZ8V6ZoMIvet83oZlJS5gOD6t2hm+YGi+N3J7zrFfvPP287uE10Yc:XN3J7zrFfvPP287uE10YbLD4uu4 |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:09:22 17:40:44+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.24 |
| CodeSize: | 322048 |
| InitializedDataSize: | 104960 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x31a000 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 432 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=14 --mojo-platform-channel-handle=5476 --field-trial-handle=3100,i,18059060334220081753,15323129114739439352,262144 --variations-seed-version /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 1 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 624 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | taskkill.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 644 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=2396 --field-trial-handle=2400,i,10971682057398369935,12635828122235481384,262144 --variations-seed-version /prefetch:2 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 732 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | 154fc53503.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 968 | "C:\Users\admin\Desktop\file.exe" | C:\Users\admin\Desktop\file.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1224 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --flag-switches-begin --flag-switches-end --do-not-de-elevate --single-argument https://apps.microsoft.com/store/detail/9MSZ40SLW145?ocid=&referrer=psi | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 1 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1304 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2204 -childID 3 -isForBrowser -prefsHandle 4760 -prefMapHandle 4756 -prefsLen 36588 -prefMapSize 244583 -jsInitHandle 1344 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {1982370b-5034-4eb1-bb0a-49a6f86cf0be} 6644 "\\.\pipe\gecko-crash-server-pipe.6644" 2328ce38bd0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 1348 | "C:\Users\admin\AppData\Local\Temp\1018678001\aed45e6ed3.exe" | C:\Users\admin\AppData\Local\Temp\1018678001\aed45e6ed3.exe | skotes.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1400 | "C:\Users\admin\AppData\Local\Temp\1018691001\d78c286d75.exe" | C:\Users\admin\AppData\Local\Temp\1018691001\d78c286d75.exe | — | skotes.exe | |||||||||||
User: admin Company: ⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫⍫ Integrity Level: MEDIUM Description: sourceFinish_setup Exit code: 0 Version: 57.9.4.48 Modules
| |||||||||||||||
| 1448 | "C:\Users\admin\AppData\Local\Temp\1018679001\587dfd33b3.exe" | C:\Users\admin\AppData\Local\Temp\1018679001\587dfd33b3.exe | 587dfd33b3.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (5788) skotes.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (5788) skotes.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (5788) skotes.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (6260) Gxtuum.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (6260) Gxtuum.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (6260) Gxtuum.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (5392) 18765d3f82.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\18765d3f82_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (5392) 18765d3f82.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\18765d3f82_RASAPI32 |
| Operation: | write | Name: | EnableAutoFileTracing |
Value: 0 | |||
| (PID) Process: | (5392) 18765d3f82.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\18765d3f82_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (5392) 18765d3f82.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\18765d3f82_RASAPI32 |
| Operation: | write | Name: | FileTracingMask |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5788 | skotes.exe | C:\Users\admin\AppData\Local\Temp\1018673001\01bfc38a74.exe | executable | |
MD5:27C1F96D7E1B72B6817B6EFEFF037F90 | SHA256:AEC3EC473DE321D123E939985579227EE62B53B3B3EDB7AB96E2A66C17E9696D | |||
| 5788 | skotes.exe | C:\Users\admin\AppData\Local\Temp\1018679001\587dfd33b3.exe | executable | |
MD5:E8AF4D0D0B47AC68D762B7F288AE8E6E | SHA256:B83449768E7AF68867C8BC42B19FF012722D88EA66AEF69DF48661E63E0EB15E | |||
| 5788 | skotes.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\NMmicronick[1].exe | executable | |
MD5:09C3F125FB23AC5BF6E7546E314F1CFD | SHA256:2E582150D30010CCA09A21F01BA47CAEA4F9A2F53469C54EE2BF1750D6F3BBCE | |||
| 968 | file.exe | C:\Windows\Tasks\skotes.job | binary | |
MD5:E8D4A9A4D53330E49F5F8D5E0A017AEA | SHA256:DEB9372D7C99110B347EA43DCDED9806F90A9E7A46AD3F62274036B6746C199B | |||
| 5788 | skotes.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\KCV3KQBA\random[1].exe | executable | |
MD5:AFD936E441BF5CBDB858E96833CC6ED3 | SHA256:C6491D7A6D70C7C51BACA7436464667B4894E4989FA7C5E05068DDE4699E1CBF | |||
| 5788 | skotes.exe | C:\Users\admin\AppData\Local\Temp\1018676001\NMmicronick.exe | executable | |
MD5:09C3F125FB23AC5BF6E7546E314F1CFD | SHA256:2E582150D30010CCA09A21F01BA47CAEA4F9A2F53469C54EE2BF1750D6F3BBCE | |||
| 5788 | skotes.exe | C:\Users\admin\AppData\Local\Temp\1018677001\d3bbebbc64.exe | executable | |
MD5:EF08A45833A7D881C90DED1952F96CB4 | SHA256:33C236DC81AF2A47D595731D6FA47269B2874B281152530FDFFDDA9CBEB3B501 | |||
| 5788 | skotes.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\random[1].exe | executable | |
MD5:27C1F96D7E1B72B6817B6EFEFF037F90 | SHA256:AEC3EC473DE321D123E939985579227EE62B53B3B3EDB7AB96E2A66C17E9696D | |||
| 4624 | NMmicronick.exe | C:\Users\admin\AppData\Roaming\Target.exe | executable | |
MD5:09C3F125FB23AC5BF6E7546E314F1CFD | SHA256:2E582150D30010CCA09A21F01BA47CAEA4F9A2F53469C54EE2BF1750D6F3BBCE | |||
| 5788 | skotes.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\E4DJRUXW\random[2].exe | executable | |
MD5:E8AF4D0D0B47AC68D762B7F288AE8E6E | SHA256:B83449768E7AF68867C8BC42B19FF012722D88EA66AEF69DF48661E63E0EB15E | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5788 | skotes.exe | GET | 200 | 31.41.244.11:80 | http://31.41.244.11/files/Krokodyl02/random.exe | unknown | — | — | unknown |
5788 | skotes.exe | POST | 200 | 185.215.113.43:80 | http://185.215.113.43/Zu7JuNko/index.php | unknown | — | — | malicious |
5788 | skotes.exe | POST | 200 | 185.215.113.43:80 | http://185.215.113.43/Zu7JuNko/index.php | unknown | — | — | malicious |
5788 | skotes.exe | GET | 200 | 31.41.244.11:80 | http://31.41.244.11/files/fate/random.exe | unknown | — | — | unknown |
5788 | skotes.exe | POST | 200 | 185.215.113.43:80 | http://185.215.113.43/Zu7JuNko/index.php | unknown | — | — | malicious |
5788 | skotes.exe | POST | 200 | 185.215.113.43:80 | http://185.215.113.43/Zu7JuNko/index.php | unknown | — | — | malicious |
5788 | skotes.exe | GET | 200 | 31.41.244.11:80 | http://31.41.244.11/files/london/random.exe | unknown | — | — | unknown |
5788 | skotes.exe | POST | 200 | 185.215.113.43:80 | http://185.215.113.43/Zu7JuNko/index.php | unknown | — | — | malicious |
5788 | skotes.exe | GET | 200 | 194.126.174.112:80 | http://194.126.174.112/files/Mnanadra/NMmicronick.exe | unknown | — | — | unknown |
5788 | skotes.exe | POST | 200 | 185.215.113.43:80 | http://185.215.113.43/Zu7JuNko/index.php | unknown | — | — | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
440 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 2.23.209.161:443 | www.bing.com | Akamai International B.V. | GB | whitelisted |
— | — | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 192.168.100.255:138 | — | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
440 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3976 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5788 | skotes.exe | 185.215.113.43:80 | — | 1337team Limited | SC | malicious |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
google.com |
| whitelisted |
sweepyribs.lat |
| malicious |
grannyejh.lat |
| malicious |
discokeyus.lat |
| malicious |
pancakedipyps.click |
| malicious |
treehoneyi.click |
| malicious |
httpbin.org |
| unknown |
home.fivetk5ht.top |
| malicious |
PID | Process | Class | Message |
|---|---|---|---|
5788 | skotes.exe | Misc Attack | ET DROP Spamhaus DROP Listed Traffic Inbound group 33 |
5788 | skotes.exe | Malware Command and Control Activity Detected | BOTNET [ANY.RUN] Amadey HTTP POST Request (st=s) |
5788 | skotes.exe | Potentially Bad Traffic | ET INFO Executable Download from dotted-quad Host |
5788 | skotes.exe | Misc Attack | ET DROP Spamhaus DROP Listed Traffic Inbound group 2 |
5788 | skotes.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
5788 | skotes.exe | Potentially Bad Traffic | ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download |
5788 | skotes.exe | Potentially Bad Traffic | ET HUNTING SUSPICIOUS Dotted Quad Host MZ Response |
2192 | svchost.exe | Domain Observed Used for C2 Detected | ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (discokeyus .lat) |
2192 | svchost.exe | Domain Observed Used for C2 Detected | ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (grannyejh .lat) |
5916 | 01bfc38a74.exe | Domain Observed Used for C2 Detected | ET MALWARE Observed Win32/Lumma Stealer Related Domain (discokeyus .lat in TLS SNI) |
Process | Message |
|---|---|
file.exe |
%s------------------------------------------------
--- Themida Professional ---
--- (c)2012 Oreans Technologies ---
------------------------------------------------
|
skotes.exe |
%s------------------------------------------------
--- Themida Professional ---
--- (c)2012 Oreans Technologies ---
------------------------------------------------
|
01bfc38a74.exe |
%s------------------------------------------------
--- Themida Professional ---
--- (c)2012 Oreans Technologies ---
------------------------------------------------
|
5420c6736f.exe |
%s------------------------------------------------
--- Themida Professional ---
--- (c)2012 Oreans Technologies ---
------------------------------------------------
|
aed45e6ed3.exe |
%s------------------------------------------------
--- Themida Professional ---
--- (c)2012 Oreans Technologies ---
------------------------------------------------
|
skotes.exe |
%s------------------------------------------------
--- Themida Professional ---
--- (c)2012 Oreans Technologies ---
------------------------------------------------
|
99de4b6e54.exe |
%s------------------------------------------------
--- Themida Professional ---
--- (c)2012 Oreans Technologies ---
------------------------------------------------
|
10eb54c21a.exe |
%s------------------------------------------------
--- Themida Professional ---
--- (c)2012 Oreans Technologies ---
------------------------------------------------
|
a269558120.exe |
%s------------------------------------------------
--- Themida Professional ---
--- (c)2012 Oreans Technologies ---
------------------------------------------------
|
f224d09151.exe |
%s------------------------------------------------
--- Themida Professional ---
--- (c)2012 Oreans Technologies ---
------------------------------------------------
|