Reading Time : 2min
This report is for information purpose only. Malware samples used in this report are actual bad pieces of software and should be handled by professionals in a safe environment. Author of this blog post is not responsible for any damage otherwise. Author does not endorse any product or service referenced or used during analysis.
Malware Family: Amadey
Sample file: Link
SHA256: 6bd20157eb146f12887ccb49fa09ac5b0c817983edc43ca1b665f17ad3ebfb25
File Type: PE32
Target OS: Windows
Testing Environment: Windows 7 x64 (No Internet Access)
File is a Spyware that collect Information, like Screenshots and Computer Information. Which can compromise everything that was visible on computer screen during infection period i.e(passwords, important documents, etc.)
c:usersappdatalocaltemp15213777301488749739
c:usersappdatalocaltemp152c6d54a1rgbux.exe
c:users*appdatalocaltemp152137773014
c:windowssystem32tasksrgbux.exe
HEKY_LOCAL_MACHINESOFTWAREMicrosoftWindows
NTCurrentVersionScheduleTaskCacheTreergbux.exe
URLs:
ProcDot:
On Virustotal 56
out of 67
Vendors Flag this file as malicious.
Timestamp: (Dec-08-2021 12:03:21 UTC)
Sample is a Spyware form Amadey malware family, it can achieve persistence by duplicating itself to the temp folder and creating entry in Task Scheduler where it runs every minute indefinitely from temp folder. Every time the malware takes screenshot of whole screen and saves it at “c:\users*\appdata\local\temp\”folder of current user random numeric name without extension. during current analysis filename was “152137773014 It also creates an empty file named “15213777301488749739” at the same location potential “.txt” for saving keystrokes.
Sample also tries to connect to below URLs potential C2.
These are simple manual steps to remove/ stop malware functioning ( might need Administrative privileges )
follow these practices to secure your cyberspace