Threat name:
Amadey, Healer AV Disabler, LummaC Steal
Alert
Classification:
rans.spre.phis.troj.spyw.evad
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code references suspicious native API functions
Antivirus / Scanner detection for submitted sample
Binary is likely a compiled AutoIt script file
C2 URLs / IPs found in malware configuration
Contains functionality to start a terminal service
Contains functionalty to change the wallpaper
Creates files in the recycle bin to hide itself
Creates HTML files with .exe extension (expired dropper behavior)
Creates multiple autostart registry keys
Detected unpacking (changes PE section rights)
Disable Windows Defender notifications (registry)
Disable Windows Defender real time protection (registry)
Disables Windows Defender Tamper protection
Drops a file containing file decryption instructions (likely related to ransomware)
Drops executable to a common third party application directory
Drops PE files with a suspicious file extension
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Found ransom note / readme
Hides threads from debuggers
Infects executable files (exe, dll, sys, html)
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
May drop file containing decryption instructions (likely related to ransomware)
May encrypt documents and pictures (Ransomware)
Modifies windows update settings
Multi AV Scanner detection for submitted file
PE file contains section with special chars
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Query firmware table information (likely to detect VMs)
Sample uses string decryption to hide its real strings
Sigma detected: Invoke-Obfuscation CLIP+ Launcher
Sigma detected: Invoke-Obfuscation VAR+ Launcher
Sigma detected: New RUN Key Pointing to Suspicious Folder
Sigma detected: Powershell download and execute file
Sigma detected: PowerShell DownloadFile
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Search for Antivirus process
Sigma detected: Suspicious MSHTA Child Process
Sigma detected: Suspicious Script Execution From Temp Folder
Suricata IDS alerts for network traffic
Suspicious powershell command line found
Tries to detect process monitoring tools (Task Manager, Process Explorer etc.)
Tries to detect sandboxes / dynamic malware analysis system (registry check)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect sandboxes and other dynamic analysis tools (window names)
Tries to detect virtualization through RDTSC time measurements
Tries to download and execute files (via powershell)
Tries to evade debugger and weak emulator (self modifying code)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Crypto Currency Wallets
Uses known network protocols on non-standard ports
Uses schtasks.exe or at.exe to add and modify task schedules
Uses the Telegram API (likely for C&C communication)
Writes a notice file (html or txt) to demand a ransom
Writes many files with high entropy
Yara detected Amadeys Clipper DLL
Yara detected Amadeys stealer DLL
Yara detected Healer AV Disabler
Yara detected LummaC Stealer
Yara detected obfuscated html page
Yara detected Powershell download and execute
Yara detected PureLog Stealer
Yara detected RedLine Stealer
Yara detected Xorist ransomware
behaviorgraph
top1
dnsIp2
2
Behavior Graph
ID:
1614837
Sample:
t5vT1k9gg6.exe
Startdate:
14/02/2025
Architecture:
WINDOWS
Score:
100
147
api.telegram.org
2->147
149
voicesharped.com
2->149
151
16 other IPs or domains
2->151
187
Suricata IDS alerts
for network traffic
2->187
189
Found malware configuration
2->189
191
Malicious sample detected
(through community Yara
rule)
2->191
195
31 other signatures
2->195
11
skotes.exe
2
51
2->11
started
16
futors.exe
2->16
started
18
t5vT1k9gg6.exe
5
2->18
started
20
6 other processes
2->20
signatures3
193
Uses the Telegram API
(likely for C&C
communication)
147->193
process4
dnsIp5
161
185.215.113.16, 49809, 49839, 49875
WHOLESALECONNECTIONSNL
Portugal
11->161
163
185.215.113.43, 49737, 49740, 49767
WHOLESALECONNECTIONSNL
Portugal
11->163
165
185.215.113.75, 49746, 49773, 49900
WHOLESALECONNECTIONSNL
Portugal
11->165
129
C:\Users\user\AppData\Local\...\DTQCxXZ.exe, PE32
11->129
dropped
131
C:\Users\user\AppData\...\ebf33b0ba9.exe, PE32
11->131
dropped
133
C:\Users\user\AppData\...\a802be2f35.exe, PE32
11->133
dropped
143
19 other files (9 malicious)
11->143
dropped
253
Found many strings related
to Crypto-Wallets (likely
being stolen)
11->253
255
Creates multiple autostart
registry keys
11->255
257
Hides threads from debuggers
11->257
259
Tries to detect process
monitoring tools (Task
Manager, Process Explorer
etc.)
11->259
22
xhvXnps.exe
5
1001
11->22
started
26
8938aab10f.exe
11->26
started
28
cmd.exe
11->28
started
38
7 other processes
11->38
167
185.215.113.209, 49857, 49869, 49916
WHOLESALECONNECTIONSNL
Portugal
16->167
169
185.215.113.97, 49888, 80
WHOLESALECONNECTIONSNL
Portugal
16->169
171
2 other IPs or domains
16->171
135
C:\Users\user\AppData\Local\...\trano1221.exe, PE32+
16->135
dropped
137
C:\Users\user\AppData\Local\...\crypted.exe, PE32
16->137
dropped
145
4 other files (2 malicious)
16->145
dropped
261
Contains functionality
to start a terminal
service
16->261
263
Tries to detect sandboxes
and other dynamic analysis
tools (process name
or module or function)
16->263
30
trano1221.exe
16->30
started
32
crypted.exe
16->32
started
139
C:\Users\user\AppData\Local\...\skotes.exe, PE32
18->139
dropped
141
C:\Users\user\...\skotes.exe:Zone.Identifier, ASCII
18->141
dropped
265
Detected unpacking (changes
PE section rights)
18->265
267
Tries to evade debugger
and weak emulator (self
modifying code)
18->267
269
Tries to detect virtualization
through RDTSC time measurements
18->269
34
skotes.exe
18->34
started
271
Suspicious powershell
command line found
20->271
273
Tries to download and
execute files (via powershell)
20->273
275
Tries to detect sandboxes
/ dynamic malware analysis
system (registry check)
20->275
36
cmd.exe
20->36
started
41
2 other processes
20->41
file6
signatures7
process8
dnsIp9
121
64 other files (40 malicious)
22->121
dropped
205
Creates files in the
recycle bin to hide
itself
22->205
207
May drop file containing
decryption instructions
(likely related to ransomware)
22->207
225
6 other signatures
22->225
109
C:\Users\user\AppData\Local\...\YeM0sAzmm.hta, HTML
26->109
dropped
209
Binary is likely a compiled
AutoIt script file
26->209
211
Creates HTA files
26->211
43
mshta.exe
26->43
started
46
cmd.exe
26->46
started
48
cmd.exe
28->48
started
51
conhost.exe
28->51
started
111
C:\Users\user\AppData\Local\...\python311.dll, PE32+
30->111
dropped
113
C:\Users\user\AppData\Local\...\_rust.pyd, PE32+
30->113
dropped
115
C:\Users\user\...\_brotli.cp311-win_amd64.pyd, PE32+
30->115
dropped
123
80 other files (2 malicious)
30->123
dropped
213
Writes many files with
high entropy
30->213
53
trano1221.exe
30->53
started
215
Queries sensitive video
device information (via
WMI, Win32_VideoController,
often done to detect
virtual machines)
32->215
217
Injects a PE file into
a foreign processes
32->217
57
2 other processes
32->57
219
Detected unpacking (changes
PE section rights)
34->219
227
4 other signatures
34->227
117
C:\Temp\APpRKYIdB.hta, HTML
36->117
dropped
60
4 other processes
36->60
153
boldcyanvas.top
104.21.33.245, 443, 49811, 49820
CLOUDFLARENETUS
United States
38->153
155
91.92.136.87
BELCLOUDBG
Cyprus
38->155
119
C:\Users\user\AppData\Local\...\futors.exe, PE32
38->119
dropped
125
5 other malicious files
38->125
dropped
221
Query firmware table
information (likely
to detect VMs)
38->221
223
Contains functionality
to start a terminal
service
38->223
229
2 other signatures
38->229
62
3 other processes
38->62
55
conhost.exe
41->55
started
file10
signatures11
process12
dnsIp13
231
Suspicious powershell
command line found
43->231
233
Tries to download and
execute files (via powershell)
43->233
64
powershell.exe
43->64
started
235
Drops PE files with
a suspicious file extension
46->235
237
Uses schtasks.exe or
at.exe to add and modify
task schedules
46->237
68
conhost.exe
46->68
started
70
schtasks.exe
46->70
started
103
C:\Temp\5JM1nf92W.hta, HTML
48->103
dropped
239
Creates HTA files
48->239
72
mshta.exe
48->72
started
74
cmd.exe
48->74
started
76
cmd.exe
48->76
started
78
4 other processes
48->78
157
floweringtstrip.help
172.67.183.104, 443, 49933, 49943
CLOUDFLARENETUS
United States
57->157
159
steamcommunity.com
23.197.127.21, 443, 49922
AKAMAI-ASN1EU
United States
57->159
241
Query firmware table
information (likely
to detect VMs)
57->241
243
Tries to harvest and
steal browser information
(history, passwords,
etc)
57->243
245
Tries to steal Crypto
Currency Wallets
57->245
80
3 other processes
60->80
105
C:\Users\user\AppData\...\Macromedia.com, PE32
62->105
dropped
247
Contains functionality
to start a terminal
service
62->247
249
Creates HTML files with
.exe extension (expired
dropper behavior)
62->249
251
Writes many files with
high entropy
62->251
82
5 other processes
62->82
file14
signatures15
process16
file17
107
TempM4NYL3PTYH01SOY1DJDDCNEOKINF60E5.EXE, PE32
64->107
dropped
173
Powershell drops PE
file
64->173
84
TempM4NYL3PTYH01SOY1DJDDCNEOKINF60E5.EXE
64->84
started
87
conhost.exe
64->87
started
175
Suspicious powershell
command line found
72->175
177
Tries to download and
execute files (via powershell)
72->177
89
powershell.exe
72->89
started
92
powershell.exe
74->92
started
94
powershell.exe
76->94
started
96
powershell.exe
78->96
started
signatures18
process19
file20
197
Detected unpacking (changes
PE section rights)
84->197
199
Modifies windows update
settings
84->199
201
Disables Windows Defender
Tamper protection
84->201
203
6 other signatures
84->203
127
C:\Users\...\483d2fa8a0d53818306efeb32d3.exe, PE32
89->127
dropped
98
483d2fa8a0d53818306efeb32d3.exe
89->98
started
101
conhost.exe
89->101
started
signatures21
process22
signatures23
179
Detected unpacking (changes
PE section rights)
98->179
181
Tries to detect sandboxes
and other dynamic analysis
tools (window names)
98->181
183
Tries to evade debugger
and weak emulator (self
modifying code)
98->183
185
3 other signatures
98->185
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.