analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

Setup_for_Windows_64_32.zip

Full analysis: https://app.any.run/tasks/d4c41845-ddcf-4088-8bdf-0b58dcc20613
Verdict: Malicious activity
Threats:

Amadey is a formidable Windows infostealer threat, characterized by its persistence mechanisms, modular design, and ability to execute various malicious tasks.

Analysis date: March 31, 2023, 19:31:14
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
amadey
loader
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

67868EBAAB6B822187F155CA206C2977

SHA1:

D3FE25BADD2E2A7A52B8084D35560322A8C70458

SHA256:

C5D8BC4D847D8313F178F08C573EDD09B7EB37FD72E8A1E83B373C78EC5AF63A

SSDEEP:

196608:wybt5vlVbAl/rcx00r+U3lfD75Rf2eqn/dIM59:wU9KjcxHZVfD7nf2eqn//

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • oneetx.exe (PID: 3572)
    • Uses Task Scheduler to run other applications

      • oneetx.exe (PID: 3572)
    • AMADEY was detected

      • oneetx.exe (PID: 3572)
    • Connects to the CnC server

      • oneetx.exe (PID: 3572)
  • SUSPICIOUS

    • Starts itself from another location

      • Setup_for_Window`s_64_32.exe (PID: 2700)
    • Reads the Internet Settings

      • Setup_for_Window`s_64_32.exe (PID: 2700)
      • oneetx.exe (PID: 3572)
    • Starts CMD.EXE for commands execution

      • oneetx.exe (PID: 3572)
      • cmd.exe (PID: 2708)
    • Application launched itself

      • cmd.exe (PID: 2708)
    • Uses ICACLS.EXE to modify access control lists

      • cmd.exe (PID: 2708)
    • The process executes via Task Scheduler

      • oneetx.exe (PID: 3836)
      • oneetx.exe (PID: 2464)
      • oneetx.exe (PID: 2712)
    • Uses RUNDLL32.EXE to load library

      • oneetx.exe (PID: 3572)
    • Process requests binary or script from the Internet

      • oneetx.exe (PID: 3572)
    • Executable content was dropped or overwritten

      • oneetx.exe (PID: 3572)
    • Connects to the server without a host name

      • oneetx.exe (PID: 3572)
  • INFO

    • Reads the computer name

      • Setup_for_Window`s_64_32.exe (PID: 2700)
      • oneetx.exe (PID: 3572)
    • Reads the machine GUID from the registry

      • Setup_for_Window`s_64_32.exe (PID: 2700)
      • oneetx.exe (PID: 3572)
    • The process checks LSA protection

      • Setup_for_Window`s_64_32.exe (PID: 2700)
      • oneetx.exe (PID: 3572)
    • Checks supported languages

      • Setup_for_Window`s_64_32.exe (PID: 2700)
      • oneetx.exe (PID: 3572)
      • oneetx.exe (PID: 3836)
      • oneetx.exe (PID: 2464)
      • oneetx.exe (PID: 2712)
    • Create files in a temporary directory

      • Setup_for_Window`s_64_32.exe (PID: 2700)
      • oneetx.exe (PID: 3572)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2368)
    • Checks proxy server information

      • oneetx.exe (PID: 3572)
    • Creates files or folders in the user directory

      • oneetx.exe (PID: 3572)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2023:03:31 11:07:24
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Setup_for_Window`s_64_32/
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
55
Monitored processes
16
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe setup_for_window`s_64_32.exe no specs setup_for_window`s_64_32.exe #AMADEY oneetx.exe schtasks.exe no specs cmd.exe no specs cmd.exe no specs cacls.exe no specs cacls.exe no specs cmd.exe no specs cacls.exe no specs cacls.exe no specs oneetx.exe no specs rundll32.exe no specs oneetx.exe no specs oneetx.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2368"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Setup_for_Windows_64_32.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\lpk.dll
c:\windows\system32\ntdll.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
3380"C:\Users\admin\AppData\Local\Temp\Rar$EXb2368.6800\Setup_for_Window`s_64_32\Setup_for_Window`s_64_32.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb2368.6800\Setup_for_Window`s_64_32\Setup_for_Window`s_64_32.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb2368.6800\setup_for_window`s_64_32\setup_for_window`s_64_32.exe
c:\windows\system32\ntdll.dll
2700"C:\Users\admin\AppData\Local\Temp\Rar$EXb2368.6800\Setup_for_Window`s_64_32\Setup_for_Window`s_64_32.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb2368.6800\Setup_for_Window`s_64_32\Setup_for_Window`s_64_32.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb2368.6800\setup_for_window`s_64_32\setup_for_window`s_64_32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
3572"C:\Users\admin\AppData\Local\Temp\eb256e24ee\oneetx.exe" C:\Users\admin\AppData\Local\Temp\eb256e24ee\oneetx.exe
Setup_for_Window`s_64_32.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\appdata\local\temp\eb256e24ee\oneetx.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\rpcrt4.dll
1820"C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN oneetx.exe /TR "C:\Users\admin\AppData\Local\Temp\eb256e24ee\oneetx.exe" /FC:\Windows\System32\schtasks.exeoneetx.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
2708"C:\Windows\System32\cmd.exe" /k echo Y|CACLS "oneetx.exe" /P "admin:N"&&CACLS "oneetx.exe" /P "admin:R" /E&&echo Y|CACLS "..\eb256e24ee" /P "admin:N"&&CACLS "..\eb256e24ee" /P "admin:R" /E&&ExitC:\Windows\System32\cmd.exeoneetx.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1112C:\Windows\system32\cmd.exe /S /D /c" echo Y"C:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
852CACLS "oneetx.exe" /P "admin:N"C:\Windows\System32\cacls.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Control ACLs Program
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\cacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\apphelp.dll
2420CACLS "oneetx.exe" /P "admin:R" /EC:\Windows\System32\cacls.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Control ACLs Program
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\cacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rpcrt4.dll
884C:\Windows\system32\cmd.exe /S /D /c" echo Y"C:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
4 516
Read events
4 422
Write events
94
Delete events
0

Modification events

(PID) Process:(2368) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2368) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2368) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2368) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2368) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2368) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2368) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2368) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2368) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2368) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
22
Suspicious files
18
Text files
334
Unknown types
0

Dropped files

PID
Process
Filename
Type
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2368.6800\Setup_for_Window`s_64_32\Globalization\Time Zone\timezones.xmlxml
MD5:18E0EF07E9049182AB229930E12E85F0
SHA256:B906F2F0C6DAB2B02A4008D101A6711125DAB9C94712953DA72B1F66421143EC
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2368.6800\Setup_for_Window`s_64_32\Language\Chinese.xmlxml
MD5:343825705C23B0A9C7FBA9BEEAAC05F5
SHA256:5707276F6917AADB4978DD13F7A421FD0A2514E17BF1352BABCDC993B22835ED
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2368.6800\Setup_for_Window`s_64_32\Language\English.xmlxml
MD5:1B997BF91F80AEDE6130CD20D9D70788
SHA256:8941745E1D14E3D92D28173CFC8BB9DD14BD6438CDC8405334241136579076A3
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2368.6800\Setup_for_Window`s_64_32\Globalization\Time Zone\timezoneMapping.xmlxml
MD5:F0281D2A00DDBBD90C9721F235B3124F
SHA256:D133EE1969118CC6048B31507497D3AF16C724A0D9CA4F666F5316785FC8A952
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2368.6800\Setup_for_Window`s_64_32\Language\Deutsch.xmlxml
MD5:5AE7BF927F6B8AD74C68FABFDE5B7EEE
SHA256:0C99D65A3A4C33D175B74784DE5F8B1DFCD81D3BB11B0D85D9DF9E8A7386FFB2
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2368.6800\Setup_for_Window`s_64_32\Language\italiano.xmlxml
MD5:D0AD2EEAE00F091E87BF7ED627EF1DDB
SHA256:ED6CA5C237939265A881FB3FAABE1D2F9FDCCDC3711E135A029CCB8581D57C27
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2368.6800\Setup_for_Window`s_64_32\Globalization\icuuc58.dllexecutable
MD5:659004D01D1DEFC4AC242B0940152C1D
SHA256:DCDEB0275B81100BC87542A78133C190F82103FEF50D3E763379934443C3BA35
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2368.6800\Setup_for_Window`s_64_32\Globalization\icuin58.dllexecutable
MD5:D69462B430EDDC76EE5AFCDD0A967DF5
SHA256:D7A7C278C8B6A96D7C085175224B34F01F55826BD81C142A56F47043A6863BE8
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2368.6800\Setup_for_Window`s_64_32\Language\Chinese Traditional.xmlxml
MD5:71E8150855B133EFC2FB99396EAC84EA
SHA256:A8113C836E805EB82FA1B26E99BFC9D230CA375AD05F2A1311F921BD18B76A5C
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2368.6800\Setup_for_Window`s_64_32\Language\Czech.xmlxml
MD5:B52A08B22245AA6737809A046994BA07
SHA256:F64F326B26F5100822DBB0F4D78291E474A0AA4F44A9332864589CD57BC8E300
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
2
DNS requests
0
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3572
oneetx.exe
POST
200
77.91.78.118:80
http://77.91.78.118/u83mfdS2/index.php?scr=1
RU
malicious
3572
oneetx.exe
GET
404
77.91.78.118:80
http://77.91.78.118/u83mfdS2/Plugins/cred.dll
RU
html
162 b
malicious
3572
oneetx.exe
GET
200
77.91.78.118:80
http://77.91.78.118/u83mfdS2/Plugins/clip.dll
RU
executable
89.0 Kb
malicious
3572
oneetx.exe
POST
200
77.91.78.118:80
http://77.91.78.118/u83mfdS2/index.php
RU
text
6 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3572
oneetx.exe
77.91.78.118:80
Foton Telecom CJSC
RU
malicious

DNS requests

No data

Threats

PID
Process
Class
Message
3572
oneetx.exe
A Network Trojan was detected
AV TROJAN Agent.DHOA System Info Exfiltration
3572
oneetx.exe
Unknown Classtype
ET MALWARE Amadey CnC Check-In
3572
oneetx.exe
A Network Trojan was detected
ET MALWARE Amadey Bot Activity (POST)
3572
oneetx.exe
Potentially Bad Traffic
ET INFO Dotted Quad Host DLL Request
3572
oneetx.exe
Potential Corporate Privacy Violation
AV POLICY HTTP request for .dll file with no User-Agent
3572
oneetx.exe
Potentially Bad Traffic
ET INFO Dotted Quad Host DLL Request
3572
oneetx.exe
Potential Corporate Privacy Violation
AV POLICY HTTP request for .dll file with no User-Agent
3572
oneetx.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
3572
oneetx.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
3572
oneetx.exe
Misc activity
ET INFO EXE IsDebuggerPresent (Used in Malware Anti-Debugging)
No debug info