9d2ca3
Amadey-downloader-dropped second-stage payload cluster. OpenCTI internal family label; co-tagged
dropped-by-amadeyacross 20+ corpus samples.Contested: The label covers at least two distinct build clusters: (1) MinGW-w64 PE32+ droppers with encrypted
.datapayloads, and (2) Go 1.25.4 PE64 infostealers with randomized module paths and fabricated Authenticode. Samplea7b9f3ddbelongs to cluster (2) but carries the same OpenCTI label. ^[/intel/analyses/a7b9f3dda435b7f2d0dfbd1e0c8d50cb824cb60fe3343a61a5fd6aa643763c4e.html]Also contested: Sample
1ba40977145dbff6f52243c28807e08847b5675f4e835bed557ed04ad37f40cdwas tagged9d2ca3by OpenCTI but is actually a Quasar/xRAT rebrand (.NET Framework 4.0 Client Profile,xClient.Corenamespace, v1.3.0.0). It shares zero build artefacts with the MinGW/Go/.NET dropper cluster. See quasar entity page.
Overview
The 9d2ca3 label groups a class of Windows x64 droppers dropped by the Amadey downloader botnet. Every observed sample follows the same build template: a MinGW-w64 PE32+ with a tiny .text section (< 50 KB) and an oversized .data section (2–3 MB) that carries the encrypted secondary payload. The import table is stripped to C runtime imports plus VirtualProtect and Sleep. No .rsrc section, no signing, no embedded icons.
All samples in this cluster have been static-only in this corpus: no CAPE Windows guest is available, and capa/floss tooling is not configured. The inner payload and C2 infrastructure remain opaque until dynamic detonation.
Build Stack
- Toolchain: MinGW-w64, LinkVersion 14.0 (GCC 14.x era).
- Format: PE32+ x86-64, 7 sections (
.text,.rdata,.data,.pdata,.00cfg,.tls,.reloc). - Linker flags: ASLR + DEP + High Entropy VA enabled; no Control Flow Guard (
.00cfgnear-empty). - Resource: Absent — no icon masquerade, no version-info masquerade.
- Signing: Unsigned across all observed samples.
- Import table: ~36 imports. Only
msvcrt.dll(CRT) andKERNEL32.dll(VirtualProtect,Sleep,SetUnhandledExceptionFilter,TlsGetValue). - Anti-analysis: Mild.
__set_app_typegate present but is standard MinGW CRT behavior. The real defense is structural: near-zero imports and an encrypted .data magazine.
Deploy / TTPs
| Technique | ID | Evidence |
|---|---|---|
| Software Packing | T1027.002 | Encrypted payload in .data section, decrypted at runtime |
| Process Injection (inferred) | T1055 | Dropper resolves payload then likely injects/hollows a child process |
| Reflective Code Loading (inferred) | T1620 | No embedded PE in static; payload shape unknown until runtime |
| Persistence (inferred) | T1547.001 | Registry Run keys used by final payload after decryption (not visible in static) |
| Sandbox Evasion (structural) | T1497.001 |
.NET 4.6.2 stage-1 stager variant (sample 8f288492 — fifth distinct morph)
A completely different build under the same opaque OpenCTI label. This is a lightweight .NET Framework 4.6.2 PE32 (~17 KB) with no packing, no obfuscation, and plaintext method names (DisableDefender, AddExclusions, DownloadPayload, AddToStartup, ExecutePayload). It does not share the MinGW, Go, or .NET 4.0 WMI fingerprints.
Key traits:
- Toolchain: .NET Framework 4.6.2 / CLR v4.0.30319, ILONLY flag,
TargetFrameworkAttribute=.NETFramework,Version=v4.6.2. - Namespace:
X7Y9Z.Q8W4K— trivially randomized, not ConfuserEx/SmartAssembly. - Build path:
D:\desktop\PROJECT MODIFY\build\bin\Debug\net462\Stub\obj\Release\net462\Stub.pdb— suggests active development, not a polished builder kit. - Anti-AV: Aggressive 11-vendor AV exclusion registry spray (ESET, AVG, Bitdefender, Kaspersky, Norton, McAfee, Tencent, Avast, 360Safe, Huorong, Windows Defender). Also disables Defender real-time monitoring via PowerShell cradle.
- Persistence: Dual —
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run(SysCore) +schtasks.exe /create /tn "SysCoreUpdate" /sc onlogon /rl highest /f. - Payload delivery: Downloads AES-encrypted payload via
System.Net.WebClientwith Chrome User-Agent, decrypts viaAesManaged, writescore.exeto staging directory. - Execution:
ShellExecutewithrunasverb for UAC elevation attempt. - Signing: Unsigned.
- C2: Payload URL runtime-resolved/encrypted; no static C2 strings.
- Dynamic: CAPE skipped (no Windows guest). All behavior inferred from static imports + strings + capa + IL inspection.
This confirms the 9d2ca3 OpenCTI label is a grab-bag covering at least five unrelated build morphs: MinGW-w64 encrypted droppers, Go 1.25.4 infostealers, .NET Framework 4.0 AES WMI hollowing dropper, and now a .NET Framework 4.6.2 lightweight anti-AV stager.
See full analysis at /intel/analyses/8f28849296f4c10a3271aec35441bc7421be693be966f749cf50120730adb348.html.
Rust wreq/boring2 engagement bot variant (sample d7c9efe8 — eighth distinct morph)
A Rust-built PE32+ x64 engagement bot for the Korean live-streaming platform SpoonCast. Uses wreq 6.0.0-rc.28 (custom HTTP client fork) backed by boring2 5.0.0-alpha.13 (BoringSSL) for TLS 1.3, with a library of ~100+ rotated browser User-Agent strings and full header/cipher-suite masquerade. No payload delivery, no persistence, no process injection — purely an HTTP worker designed to inflate viewership metrics.
Key traits:
- Toolchain: Rust stable
x86_64-pc-windows-msvc, compiled May 29 2026 ^[/intel/analyses/d7c9efe83a46acea1c8a012e0ac0b697c3b6bc282d192d2b07cf2361d8fd8345.html] - Format: PE32+ x64, 5 sections, 7.3 MB
- Dependencies:
tokio-1.52.3,wreq-6.0.0-rc.28,http2-0.5.17,boring2-5.0.0-alpha.13,tokio-boring2-5.0.0,flate2-1.1.9,url-2.5.8,idna-1.1.0,icu_normalizer-2.2.0 - Target endpoint:
https://kr-hana-live.spooncast.net/cast/ - Masquerade: Chrome/Edge/Firefox/Opera/Safari UA rotation across Windows, macOS, Linux, Android, iOS; TLS 1.3 with post-quantum hybrid
X25519MLKEM768key exchange - Proxy support: Reads standard
*_PROXYenvironment variables; CONNECT tunnel capability - Signing: Unsigned
- Dynamic: CAPE skipped (no Windows guest)
This confirms 9d2ca3 now spans at least eight distinct morphs.
See full analysis at /intel/analyses/d7c9efe83a46acea1c8a012e0ac0b697c3b6bc282d192d2b07cf2361d8fd8345.html.
MinGW-w64 reflective downloader variant (sample 022fe01a — sixth distinct morph)
A pure MinGW-w64 x64 downloader/loader with no embedded payload. Instead of decrypting a local .data section, it hardcodes an XOR-obfuscated C2 URL, downloads the secondary stage over HTTP, and maps it reflectively into RWX memory.
Key traits:
- Toolchain: MinGW-w64 GCC 15.2.0 (MSYS2 Rev8), compiled May 28 2026 ^[/intel/analyses/022fe01a4fb8855747a4068de2131ceb7486cf846df6c18adbefe7564482adb5.html]
- Architecture check: Resolves
IsWow64Processdynamically viaGetModuleHandleA+GetProcAddress, aborts on mismatch ^[/intel/analyses/022fe01a4fb8855747a4068de2131ceb7486cf846df6c18adbefe7564482adb5.html] - C2 decode: Five
movabsqword constants XOR-decoded with key0xAAinmain()→http://89.125.188.171/nah11/file.exe^[/intel/analyses/022fe01a4fb8855747a4068de2131ceb7486cf846df6c18adbefe7564482adb5.html] - Download: WinHTTP with hardcoded User-Agent
"Lak2oes", plain HTTP GET, streams response intomalloc'd buffer ^[/intel/analyses/022fe01a4fb8855747a4068de2131ceb7486cf846df6c18adbefe7564482adb5.html] - Reflective load: Hand-written PE mapper (
LoadPERaw) validates MZ/PE/AMD64, allocates RWX memory, copies sections, resolves imports viaLoadLibraryA/GetProcAddress, applies relocations, and jumps to entry point ^[/intel/analyses/022fe01a4fb8855747a4068de2131ceb7486cf846df6c18adbefe7564482adb5.html] - No persistence, no registry — fire-and-forget downloader stub
- Signing: Unsigned
- Dynamic: CAPE skipped (no Windows guest)
See full analysis at /intel/analyses/022fe01a4fb8855747a4068de2131ceb7486cf846df6c18adbefe7564482adb5.html.
Rust ureq/rustls downloader variant (sample 4c25af57 — seventh distinct morph)
The first Rust-built sibling in the cluster. A stripped PE32+ x64 downloader using the ureq 2.12.1 HTTP client backed by rustls 0.23.36 and ring 0.17.14 for TLS 1.3 payload retrieval. Hardcodes a single HTTPS C2 URL (https://cloud.white-monster.xyz/cat.jpg) and a SHA-256 payload integrity hash. No embedded payload, no persistence, no process injection visible statically.
Key traits:
- Toolchain: Rust ~1.92.0 stable (rustc commit
59807616, 2026-04-14), LLD 2.44 ^[/intel/analyses/4c25af5791f7cad042fbfc6dca3ae78b7344c66f9f3a35853e76565bae0890f3.html] - Format: PE32+ x64, 10 sections (
.text,.data,.rdata,.pdata,.xdata,.bss,.idata,.tls,.rsrc,.reloc) - Dependencies:
ureq2.12.1,rustls0.23.36,ring0.17.14,flate21.1.8,base640.22.1,url2.5.8,idna1.1.0,once_cell1.21.3,smallvec1.15.1,crc32fast1.5.0 - C2:
https://cloud.white-monster.xyz/cat.jpg— hardcoded in.rdata - Payload integrity: SHA-256
867fbc90e07b14f8b5884fdc2993bfefd900a635e08ae5bfccc42e4b9ae59398hardcoded in.rdata - TLS: TLS 1.3 capable via
rustls; ECH strings present but configuration unknown statically - Signing: Unsigned
- Dynamic: CAPE skipped (no Windows guest)
This confirms 9d2ca3 now spans at least seven distinct morphs.
See full analysis at /intel/analyses/4c25af5791f7cad042fbfc6dca3ae78b7344c66f9f3a35853e76565bae0890f3.html.
Go cluster variant (sample a7b9f3dd)
A distinct second-stager under the same label. Build fingerprint:
- Toolchain: Go 1.25.4,
CGO_ENABLED=0,trimpath=true - Module path: randomized per-build (e.g.
uyiUNvZdvAGQnhv) - Function names: ~28 randomized main-package symbols visible in
.symtab - Signing: Fabricated Authenticode (PE security dir with leaf CN=
askart.com, issuer=WE1) - Anti-analysis: No static C2, no .rsrc, junk delay loops in
main.Jtruwhtr - Behaviour:
VirtualAllocresolved via Gosyscall._LazyProc_; probable in-memory payload staging
See full analysis at /intel/analyses/a7b9f3dda435b7f2d0dfbd1e0c8d50cb824cb60fe3343a61a5fd6aa643763c4e.html.
Go cluster variant (sample 29149758 — newer sibling)
Second observed Go infostealer under the same label, with significant builder drift:
- Toolchain: Go 1.25.4,
CGO_ENABLED=0,trimpath=true - Module path:
wqeHivEQWBGOQgj(randomized) - Function names: 39 randomized main-package symbols (up from 28 in a7b9f3dd)
- Signing: Same fabricated Authenticode serial as sibling
cc4aa789(CDDA1164C88E40890E189788E7C9F32B, CN=askart.com, issuer=WE1) - Anti-analysis: Fused-string API decoding — DLL/API names are concatenated into
.rdatablobs and sliced at runtime viasyscall._LazyProc_; no standaloneVirtualAllocstring in static output - Behaviour: Custom in-memory PE export walker (
main.fvcmychoeu), PRNG-seeded delay loops (main.Wqmcsrfqooezj), host fingerprinting (hostname,PID,pagesize), then enters an idle GUI loop - Size: 12 MB (vs ~2.5 MB for a7b9f3dd) — suggests embedded payload or expanded string tables
See full analysis at /intel/analyses/2914975816372d0dc79b777915f66955d312213ea036b84ff16ad5ab0bcfdd66.html.
Go cluster variant (sample 389e1ccf — third sibling)
Third Go infostealer under the same label, confirming the cluster build pipeline:
- Toolchain: Go 1.25.4,
CGO_ENABLED=0,trimpath=true,GOARCH=amd64,GOAMD64=v1 - Module path:
LUOegnbUmXZeMZT(randomized) - Function names: 43 randomized
main.*identifiers (upward trend in symbol count) - Signing: Fabricated Authenticode with
godaddy.comstring andWE1marker in certificate blob; malformed ASN.1 blocks direct parsing — consistent with fabricated certs in siblings - Anti-analysis: Same fused-string API decoding pattern (
advapi32.dllGetUserNameAVirtualAllocrandautoseedsweepWaiters...) - Behaviour: PRNG seed from system clock → sequential dispatch of 24 worker functions →
hostname/PID/pagesizeread → idle GUI loop - Size: 2.48 MB (typical for this cluster)
- Filename:
EclipseV2.exe(masquerade)
See full analysis at /intel/analyses/389e1ccf072f134de9d3b007df0952f43f2dc0c3a4f55fbe6f3035d1d0c14dc0.html.
.NET dropper variant (sample 2bf8e65c — fourth distinct morph)
A completely different build under the same opaque OpenCTI label. This is a .NET Framework 4.0 x64 PE compiled May 22 2026, internal name popit.exe, with a 2.1 MB IL-only .text section and a tiny .rsrc containing only the manifest. It does not share the MinGW or Go fingerprints observed in every prior sibling.
Key traits:
- Toolchain: .NET Framework 4.0 / CLR v4.0.30319, ILONLY flag, EntryPointToken
0x06000001. - Payload delivery: Base64 + AES (
RijndaelManaged+Rfc2898DeriveBytes) encrypted ZIP, extracted in-memory viaSystem.IO.Compression.ZipArchive. No embedded RCData or secondary PE in.rsrc. - Injection: P/Invoke imports for
CreateProcess,VirtualAllocEx,WriteProcessMemory,ZwUnmapViewOfSection,SetThreadContext,ResumeThread— textbook process hollowing. - Process targeting: WMI
ManagementObjectSearcherqueriesWin32_Processfor candidate host processes to hollow. - Privilege elevation: Manifest requests
requireAdministrator. - Network hardening: Enforces TLS 1.2 via
ServicePointManager.SecurityProtocol. - Obfuscation: Garbage identifiers (
flecduep,knzhwyemdmfotslhxivggphauaduuuzem, etc.) in metadata; no ConfuserEx / SmartAssembly name mangling. - Signing: Unsigned.
- C2: None in static; C2 config is runtime-decrypted by the inner payload.
- Dynamic: CAPE skipped (no Windows guest). All behavior inferred from static imports + strings + capa.
This sample confirms the 9d2ca3 OpenCTI label is a grab-bag covering at least three unrelated build morphs: MinGW-w64 encrypted droppers, Go 1.25.4 infostealers, and now a .NET Framework 4.0 AES dropper with WMI hollowing.
See full analysis at /intel/analyses/2bf8e65cde6c51c07492255eb11f9ef2d7f02c5bd0337c1e7b1c9266d73843ce.html.
Notable Analyses
/intel/analyses/2d39ed5ea7f2547233f534c4e78edef047051c26c115ac120663705be96b8e5d.html— Deep-dive on the MinGW-w64 shell, oversized.datadecryption, and structural anomalies.
Capabilities
oversized-encrypted-data-sectionmingw-w64-build-artifactsminimal-import-tablevirtualprotect-memory-remappingsleep-delay-anti-sandboxdata-section-payload-decryptiongo-lazyproc-virtualalloc-runtime-resolutionfused-string-api-decodinggo-custom-pe-export-walkerprng-seeded-sandbox-delayhost-fingerprinting-idle-loopdotnet-aes-base64-resource-decryptionwmi-process-enumerationprocess-hollowing-via-pinvoketls-1.2-enforcementmanifest-admin-elevationdotnet-stub-no-obfuscationav-registry-exclusion-spraydefender-disable-powershellwebclient-aes-payload-downloadschtasks-onlogon-persistenceshellexecute-runas-elevationchrome-ua-masqueradexor-movabs-c2-url-decodewinhttp-plain-http-gethardcoded-user-agent-masqueradeiswow64process-arch-checkreflective-pe-loader-in-rwxrust-ureq-rustls-downloaderrust-wreq-boring2-engagement-botspooncast-viewbot-ua-rotationtls-1.3-post-quantum-hybridproxy-env-var-tunneltls-1.3-ech-capablehardcoded-sha256-payload-integrityjpg-masquerade-payload-delivery
Related
- peb-walking-api-resolution — Some Amadey payloads use PEB export-hash walking for API resolution, though this stub relies on the import table.
- Amadey downloader (external, Malpedia
win.amadey) — the upstream delivery mechanism for this cluster.