d52f85
OpenCTI internal family label for payloads dropped by the Amadey downloader botnet. In this corpus,
d52f85has been observed on a Counter-Strike 2 external cheat overlay (sample2fb095b1), distinct from the9d2ca3Amadey cluster. The label is best treated as a distribution-channel grouping rather than an intrinsic malware family.
Overview
OpenCTI assigns d52f85 to samples co-tagged dropped-by-amadey. The PacketPursuit corpus has now observed two distinct build morphs under this label:
- CS2 "Cheetah" external cheat (
2fb095b1) — 4.6 MB MSVC 14.50 PE32+ overlay cheat with ImGui, NtRead/WriteVirtualMemory, no packing. ^[/intel/analyses/2fb095b1ad49aa816bc15a373bc7ffdf70eddc37a66e0f647c834d4413290150.html] - Themida-packed Ubisoft Connect masquerade (
78434b53) — 3.3 MB PE32+ x64 with Themida/WinLicense.bootdecompressor, forged Ubisoft Connect version-info, six PNG icons, and a fabricated self-signed CN=Lightshotcertificate with DigiCert timestamp counter-signature. The actual malicious payload is fully encrypted inside the.bootstub. ^[/intel/analyses/78434b53d284d4537e6d44a9373da8ef86d15c0cd36f32ce695dfd82db7eccfd.html]
Unlike the 9d2ca3 cluster — which contains MinGW droppers, Go infostealers, and .NET hollowing payloads — these samples share only the Amadey delivery channel. The label is best treated as a distribution-channel grouping rather than an intrinsic malware family.
Build Stack
Two confirmed morphs under this distribution label:
Morph A: CS2 "Cheetah" external cheat (2fb095b1)
- Toolchain: MSVC 14.50 (Visual Studio 2022 v143), C++20, UCRT/ConCRT runtime.
- Format: PE32+ x86-64, 6 sections (
.text,.rdata,.data,.pdata,.rsrc,.reloc). - Linker flags: ASLR + DEP + High Entropy VA; Terminal Server Aware.
- Signing: Unsigned.
- PDB:
C:\Users\nikor\source\repos\cheetah\x64\Release\cheetah.pdb— developer identity leak. - Obfuscation / packing: None. No UPX, Themida, VMProtect, or custom packer. Section entropies (6.29–6.67) are consistent with compiled C++ + ImGui + embedded font bitmaps.
- Anti-analysis: None observed. No anti-VM, anti-debug, or sandbox gating.
Morph B: Themida-packed Ubisoft Connect masquerade (78434b53)
- Toolchain: MSVC 14.29 (Visual Studio 2019 v142), C/C++.
- Format: PE32+ x86-64, 8 sections (5 blank-name,
.rsrc,.idata,.themida,.boot). - Linker flags: ASLR + DEP + High Entropy VA; Terminal Server Aware.
- Signing: Fabricated self-signed CN=
Lightshotwith DigiCert timestamp counter-signature (post-dated 2026). - Packing: Themida/WinLicense —
.themidaplaceholder (virtual-only),.bootLZ77 decompressor stub, blank section names, 3 imports (GetModuleHandleA, GetActiveWindow, BitBlt). - Masquerade: Complete Ubisoft Connect version-info (v4.1.9718.720), XML assembly manifest, 6 PNG icons (256×256 to 16×16).
- Anti-analysis: Heavy Themida obfuscation eliminates static API surface; actual payload encrypted/compressed inside
.boot.
Deploy / TTPs
| Technique | ID | Evidence |
|---|---|---|
| Process Injection (cross-process memory manipulation) | T1055.012 | NtReadVirtualMemory, NtWriteVirtualMemory against cs2.exe / client.dll ^[/intel/analyses/2fb095b1ad49aa816bc15a373bc7ffdf70eddc37a66e0f647c834d4413290150.html] |
| Input Capture (API hooking / synthesis) | T1056.004 | NtUserInjectMouseInput, NtUserInjectKeyboardInput via win32u.dll for aimbot input injection |
| Discovery: Process Discovery | T1057 | CreateToolhelp32Snapshot, K32EnumProcessModulesEx, Process32FirstW/NextW to enumerate target game modules |
| Collection: Screen Capture | T1113 | ImGui overlay + screenshot capability used for ESP/radar |
| Defense Evasion: Masquerading | T1036 | "Essentials External v1.3" branding; game-cheat masquerade |
Capabilities
themida-packed-lz77-decompressorversion-info-masqueradecertificate-fabrication-self-signedtimestamp-counter-signature-masqueradeembedded-icon-suite-masqueradeexternal-process-memory-readexternal-process-memory-writeinput-injection-mouse-keyboardgame-state-schema-loader-jsonimgui-overlay-renderaimbot-prediction-smoothingesp-team-visibility-filterchams-wireframe-rimlightradar-overlay-mini-maprecoil-control-systemvelocity-bunny-hop-assistcreate-toolhelp-process-discoveryno-c2-self-containedadmin-elevation-gate
Notable Analyses
/intel/analyses/2fb095b1ad49aa816bc15a373bc7ffdf70eddc37a66e0f647c834d4413290150.html— Deep static analysis of the CS2 "Cheetah" external cheat./intel/analyses/78434b53d284d4537e6d44a9373da8ef86d15c0cd36f32ce695dfd82db7eccfd.html— Themida-packed Ubisoft Connect masquerade with fabricated Lightshot certificate.
Related
- 9d2ca3 — Amadey-downloader-dropped second-stage payload cluster (MinGW + Go + .NET variants). Shares the
dropped-by-amadeyco-label but is build-distinct from this sample. - Amadey downloader (external, Malpedia
win.amadey) — the upstream delivery mechanism.