국내 유명 메신저 프로그램으로 위장하여 유포 중인 Amadey Bot
2022-10-17 • Ahnlab • Amadey Bot is being distributed disguised as a famous domestic messenger program. •
AhnLab analyzes Amadey Bot malware distributed as a fake KakaoTalk update during public concern over Kakao service disruptions. The initial executable used the messenger program’s name and icon, recursively relaunched itself, injected into its own process, and downloaded a ZIP payload to the public folder. The dropper launched a DLL through rundll32.exe, creating and executing an Amadey Bot component that reported host ID, version, privilege level, architecture, Windows version, PC name, and username to its C2 server. The report provides detections, hashes, and URLs for the downloader, dropper, and Amadey payload.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 0184b0f6403420f7134a3e4a37498754 | 2022-10-17 | 2022-10-17 |
| HASH | ccd5a8f11035b888a7a3de6035ac272e | 2022-10-17 | 2022-10-17 |
| HASH | 00a7588c41c5a1183f098901d30df09a | 2022-10-17 | 2022-10-17 |
| URL | https://office-download3791.com… | 2022-10-17 | 2022-10-17 |
| URL | https://rs-shop7301.com/index.p… | 2022-10-17 | 2022-10-17 |
| DOMAIN | rs-shop7301.com | 2022-10-17 | 2022-10-17 |
| DOMAIN | office-download3791.com | 2022-10-17 | 2022-10-17 |