General

  • Target

    2025-05-08_24934f660627807792fca2ca0252616b_amadey_elex_rhadamanthys_smoke-loader

  • Size

    134KB

  • Sample

    250508-y1mkasap8x

  • MD5

    24934f660627807792fca2ca0252616b

  • SHA1

    24b35f9232d76e286492d93ee9b20db4a3010e0e

  • SHA256

    cf078da5e81b5f159fd6201bc9654bebb59cc52af42936f8387f73cd5a4782b7

  • SHA512

    494cee4f80be3a3f81012538b21ae2a68e15ce316bbb39bcdf7291ebabe9c7791665a62af2aad6ad166eaa2ac3e278deeb4d26a7e31e71d8ca3e9df5c6de6464

  • SSDEEP

    1536:XDfDbhERTatPLTH0iqNZg3mqKv6y0RrwFd1tSEsF27da6ZW72Foj/MqMabadwCil:ziRTeH0iqAW6J6f1tqF6dngNmaZCiaI

Malware Config

Extracted

Family

neconyd

C2

http://ow5dirasuek.com/

http://mkkuei4kdsz.com/

http://lousta.net/

Targets

    • Target

      2025-05-08_24934f660627807792fca2ca0252616b_amadey_elex_rhadamanthys_smoke-loader

    • Size

      134KB

    • MD5

      24934f660627807792fca2ca0252616b

    • SHA1

      24b35f9232d76e286492d93ee9b20db4a3010e0e

    • SHA256

      cf078da5e81b5f159fd6201bc9654bebb59cc52af42936f8387f73cd5a4782b7

    • SHA512

      494cee4f80be3a3f81012538b21ae2a68e15ce316bbb39bcdf7291ebabe9c7791665a62af2aad6ad166eaa2ac3e278deeb4d26a7e31e71d8ca3e9df5c6de6464

    • SSDEEP

      1536:XDfDbhERTatPLTH0iqNZg3mqKv6y0RrwFd1tSEsF27da6ZW72Foj/MqMabadwCil:ziRTeH0iqAW6J6f1tqF6dngNmaZCiaI

    • Neconyd

      Neconyd is a trojan written in C++.

    • Neconyd family

    • Executes dropped EXE

    • Drops file in System32 directory

    • Suspicious use of SetThreadContext

MITRE ATT&CK Enterprise v16

Tasks

OSZAR »