국내 유명 메신저 프로그램으로 위장하여 유포 중인 Amadey Bot

2022-10-17 Ahnlab Amadey Bot is being distributed disguised as a famous domestic messenger program.

https://asec.ahnlab.com/ko/40107/

Thumbnail for 국내 유명 메신저 프로그램으로 위장하여 유포 중인 Amadey Bot

AhnLab analyzes Amadey Bot malware distributed as a fake KakaoTalk update during public concern over Kakao service disruptions. The initial executable used the messenger program’s name and icon, recursively relaunched itself, injected into its own process, and downloaded a ZIP payload to the public folder. The dropper launched a DLL through rundll32.exe, creating and executing an Amadey Bot component that reported host ID, version, privilege level, architecture, Windows version, PC name, and username to its C2 server. The report provides detections, hashes, and URLs for the downloader, dropper, and Amadey payload.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 0184b0f6403420f7134a3e4a37498754 2022-10-17 2022-10-17
HASH ccd5a8f11035b888a7a3de6035ac272e 2022-10-17 2022-10-17
HASH 00a7588c41c5a1183f098901d30df09a 2022-10-17 2022-10-17
URL https://office-download3791.com… 2022-10-17 2022-10-17
URL https://rs-shop7301.com/index.p… 2022-10-17 2022-10-17
DOMAIN rs-shop7301.com 2022-10-17 2022-10-17
DOMAIN office-download3791.com 2022-10-17 2022-10-17

Related Reports

« Back