logo

Technical Analysis of a Novel IMEEX Framework

ID: 1b2033da-4b35-5e65-817a-629f69930859

STIX ID: report--1b2033da-4b35-5e65-817a-629f69930859

Feed Name: Intezer Blog

Threat Score
85/100

Date Published: 2024-10-10

Date Updated: 2026-04-28

Author: Nicole Fishbein

...
...

IMEEX is a custom 64-bit Windows remote access framework observed in samples submitted from Djibouti and Afghanistan; it performs system reconnaissance, file and process management, registry manipulation, dynamic module loading, and encrypted C2 communications (commonly over TCP/443). The report provides sample hashes, C2 domains and IPs (e.g., yurtumawat.wwwhost.us, erkinhorshiden.onedumb.com, bbsnews.sytes.net, 45.141.139.146), mutexes, Registry locations used for module tracking, Python decoding scripts, and a YARA detection rule; analysts note possible infrastructure overlap with ShadowPad but do not claim definitive attribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.