Analytics Story: Amadey

Description

This analytic story contains searches that aims to detect activities related to Amadey, a type of malware that primarily operates as a banking Trojan. It is designed to steal sensitive information such as login credentials, credit card details, and other financial data from infected systems. The malware typically targets Windows-based computers.

Why it matters

Amadey is one of the active trojans that are capable of stealing sensitive information via its from the infected or targeted host machine. It can collect various types of data, including browser profile information, clipboard data, capture screenshots and system information. Adversaries or threat actors may use this malware to maximize the impact of infection on the target organization in operations where data collection and exfiltration is the goal. The primary function is to steal information and further distribute malware. It aims to extract a variety of information from infected devices and attempts to evade the detection of security measures by reducing the volume of data exfiltration compared to that seen in other malicious instances.

Detections

Name ▲▼ Technique ▲▼ Type ▲▼
Detect Outlook exe writing a zip file Spearphishing Attachment Anomaly
Windows ISO LNK File Creation Malicious Link, Spearphishing Attachment Hunting
Windows Suspicious Process File Path Match Legitimate Resource Name or Location, Create or Modify System Process TTP
Windows Credentials from Password Stores Chrome Login Data Access Query Registry Anomaly
Windows Powershell RemoteSigned File PowerShell Anomaly
Suspicious Process Executed From Container File Masquerade File Type, Malicious File TTP
Executables Or Script Creation In Temp Path Masquerading Anomaly
WinEvent Windows Task Scheduler Event Action Started Scheduled Task Hunting
Windows Credentials from Password Stores Chrome LocalState Access Query Registry Anomaly
Process Creating LNK file in Suspicious Location Spearphishing Link Anomaly
Scheduled Task Deleted Or Created via CMD Scheduled Task Anomaly
Executables Or Script Creation In Suspicious Path Masquerading Anomaly
Windows Credentials from Password Stores Chrome Extension Access Query Registry Anomaly
Registry Keys Used For Persistence Registry Run Keys / Startup Folder TTP
Windows Files and Dirs Access Rights Modification Via Icacls Windows Permissions Anomaly

Data Sources

Name ▲▼ Platform ▲▼ Sourcetype ▲▼ Source ▲▼
Sysmon EventID 1 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Sysmon EventID 11 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
CrowdStrike ProcessRollup2 Other crowdstrike:events:sensor crowdstrike
Windows Event Log Security 4688 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security
Windows Event Log Security 4663 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security
Windows Event Log TaskScheduler 201 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security
Windows Event Log TaskScheduler 200 Windows icon Windows wineventlog WinEventLog:Microsoft-Windows-TaskScheduler/Operational
Sysmon EventID 13 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational

References


Source: GitHub | Version: 2