Analyzing Amadey
ID: 50f2606a-17ad-518e-9275-52b255162a52
STIX ID: report--50f2606a-17ad-518e-9275-52b255162a52
Feed Name: Nao_Sec
Threat Score
This report presents an excerpt of a malware analysis showing obfuscated configuration data (e.g., domain, RunDll, URLMon, DropDir, AutoRun) and a simple decoder loop that subtracts key bytes from encoded values to recover plaintext, illustrating the sample’s string‑obfuscation technique and likely revealing C2 and operational artifacts once decoded.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
