• Services
    • Assess
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Transform
      • SOC Consultancy
      •     SOC Maturity Assessment
      •     SOC Model Evaluation
      •     SOC Gap Analysis
      •     SIEM Gap Analysis
      •     SIEM Optimization
      •     SOC Content Pack
    • Train
      • Security Awareness and Training
      • Tabletop Exercise
      • Simulated Cyber Attack Exercises
    • Respond
      • Incident Response
      • Incident Analysis
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Press Release
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
Rewterz Threat Alert – Phobos Ransomware – Active IOCs
December 22, 2022
Rewterz Threat Alert – APT SideWinder Group Targeting Pakistan – Active IOCs
December 23, 2022

Rewterz Threat Alert – Amadey Botnet – Active IOCs

December 23, 2022

Severity

High

Analysis Summary

Amadey infects a victim’s computer and incorporates it into a. botnet. The Amadey trojan can also download additional malware. and exfiltrate user information to a command and control (C2) server. Moreover, it can engage the victim’s system. The threat actor sent spam emails that reference a package or shipment. Many of the emails claim in the subject line that the package or shipment is from the shipping company DHL. For example, one subject line is “You have a package coming from DHL.” The bodies of all of the emails we observed in this campaign are blank. Each email has a ZIP attachment containing a Visual Basic Script (VBS) file. Each file name for the ZIP files is a series of numbers separated by an underscore, such as 044450_64504154.zip. The VBS files have the same name as their ZIP file, except they have the VBS extension rather than the ZIP extension.

Impact

  • Information Theft
  • Exposure of Sensitive Data

Indicators of Compromise

MD5

  • 9305696f20a25c6b4e09ee58fcda8111
  • 0ce2f5738c555867316ed927d449d155
  • 36422190975ad573a4ef5782dd486f02
  • edc2315fb8845723b55e4dee82f7c3dc

SHA-256

  • 9b5569c70506b827fe1e38b2477e7134b8642c5f0e2dffb39699daa1eecebb32
  • ad68196391c11404677874d5d3269caa79a1a821a565dd8678de20429f214b51
  • 81dd8adee2eb662a18a594c579b3f3892235f1cbae36e818ce9fe85e86af9e20
  • 2f61fe794a8ed6ae7dfb86507dc19684083a9087b01a952420da34ca8648ef09

SHA-1

  • fda95ce07f8665da382a61e39f56334f5c2ac678
  • 03e22670104467ab5d0f2f1e6966bd11fe5ae100
  • e91aa11ad050aa392ecdb27c2cc5f791cbd7fd5e
  • ff3c1701d71919054ee983aa18310c2a830d4ef5

Remediation

  • Upgrade your operating system.
  • Don’t open files and links from unknown sources.
  • Install and run anti-virus scans.
  • Services
    • Assess
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Respond
      • Incident Response
      • Incident Analysis
  • Transform
    • SOC Consultancy
    •     SOC Maturity Assessment
    •     SOC Model Evaluation
    •     SOC Gap Analysis
    •     SIEM Gap Analysis
    •     SIEM Optimization
    •     SOC Content Pack
  • Train
    • Security Awareness and Training
    • Tabletop Exercise
    • Simulated Cyber Attack Exercises
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
COPYRIGHT © REWTERZ. ALL RIGHTS RESERVED.