국내 유명 메신저 프로그램으로 위장하여 유포 중인 Amadey Bot

2022-10-17 • Ahnlab • Amadey Bot is being distributed disguised as a famous domestic messenger program. •

https://asec.ahnlab.com/ko/40107/

Thumbnail for 국내 유명 메신저 프로그램으로 위장하여 유포 중인 Amadey Bot

AhnLab analyzes Amadey Bot malware distributed as a fake KakaoTalk update during public concern over Kakao service disruptions. The initial executable used the messenger program’s name and icon, recursively relaunched itself, injected into its own process, and downloaded a ZIP payload to the public folder. The dropper launched a DLL through rundll32.exe, creating and executing an Amadey Bot component that reported host ID, version, privilege level, architecture, Windows version, PC name, and username to its C2 server. The report provides detections, hashes, and URLs for the downloader, dropper, and Amadey payload.

Indicators of Compromise

Type Value First Seen Last Seen
HASH e752653fba1bdf7bdd9fd285b011cef… 2022-10-17 2022-10-17
HASH 9134dbb0be87ad3c111a4bad5a6aae8… 2022-10-17 2022-10-17
HASH f86d6ea1cd680e702735d2f35726a0d… 2022-10-17 2022-10-17
URL https://office-download3791.com… 2022-10-17 2022-10-17
URL https://rs-shop7301.com/index.p… 2022-10-17 2022-10-17
DOMAIN rs-shop7301.com 2022-10-17 2022-10-17
DOMAIN office-download3791.com 2022-10-17 2022-10-17

Related Reports

« Back