RMM

Ammyy Admin

Ammyy Admin is a remote monitoring and management (RMM) tool. Ammyy admin has been used by scammers to gain remote access to victims' computers. The tool is legitimate and is used by IT professionals for remote management. However, it has been abused by scammers to gain unauthorized access to victims' computers. The tool is free for personal use, but a license is required for commercial use. The tool allows for remote desktop control, file transfer, voice chat, and more. The tool is available for Windows only. will be added as it becomes available.

Tool overview

Category
RMM
Research authors
@kostsatsale
Created
2024-05-08
Last modified
2024-05-08
Privileges
Curent User
Free / availability
Yes/1 active session at a time
Verification required
None
Supported platforms
Windows

Capabilities

Remote Management sessionRDP ConnectionFile TransferVoice Chat

Known vulnerabilities

  • CVE-2013-5582

Executables & installation paths

Filename
AA_v3.exe
OriginalFileName
Not recorded
Description
Ammyy Admin

Installation paths

C:\\ProgramData\\AMMYY\\*
AMMYY_Admin.exe
aa_v*.exe
C:\Users\*\Downloads\AMMYY_Admin.exe
*\AMMYY_Admin.exe

FORENSIC EVIDENCE

Disk artifacts

File
%programdata%\\AMMYY\\access.log
Description
Ammyy Admin access log file. Contains information about the remote IP address, the time of connection, bytes recv/send, and the ID of the remote machine.
OS
Windows
Example
  • 20240805-22:20:45.962000 00000D98 - [0] PASSED authorization remoteId=XXXXXXXX; TCP by router 136.243.104.235:443
  • 20240805-22:22:34.139000 00000710 - [1] FAILED authorization remoteId=XXXXXXXX; TCP by router 136.243.104.235:443
  • 20240805-22:23:10.648000 00000D98 - [0] ENDED authorized session, bytes recv/send = 1164 / 115378
File
%Binary_path%\\AA_v3.log
Description
Ammyy Admin log file. Contains application related logs.
OS
Windows
Example
  • 20240805-22:19:52.455000 00001318 - ERROR: ERROR: 2 RLEvent::TryToOpen(Global\AANS_FvwjZ_CHI)
  • 20240805-22:23:10.648000 00000D98 - ERROR: ERROR SetThreadDesktop(200) 170

FORENSIC EVIDENCE

Event log artifacts

EventID
4688
ProviderName
Microsoft-Security-Auditing
LogFile
Security.evtx
CommandLine
rundll32.exe "C:\ProgramData\AMMYY\aa_nts.dll",run
Description
Execution of Ammyy Admin
EventID
7045
ProviderName
Service Control Manager
LogFile
System.evtx
ServiceName
Ammyy Admin
ImagePath
C:\*\AA_v3.exe
Description
Ammyy Admin service installation event

FORENSIC EVIDENCE

Registry artifacts

Path
HKU\.DEFAULT\Software\Ammyy\Admin
Key
hr3
Type
Reg_Binary
Description
Writing the hr3 binary in the registry. The hr3 is likely used to store admin-related information.
Path
HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\AmmyyAdmin
Description
Ammyy Admin service allows AMMYY admin to run in safe mode.

FORENSIC EVIDENCE

Network artifacts

Description
Known remote domains and router IP addresses
Domains
  • ammyy.com
  • *.ammyy.com
Ports
  • 5931
  • 80
  • 443
  • 8080
Description
Known router IP addresses (TCP connections)
Domains
  • 136.243.104.235
  • 136.243.104.242
  • 136.243.18.122
Ports
  • 443

Detections

Sigma
https://github.com/tsale/Sigma_rules/blob/main/Threat%20Hunting%20Queries/ammyy_admin.yml
Name
Detecting Ammy Admin RMM Agent Execution
Description
Detects the execution of the Ammy Admin RMM agent for remote management.
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/ammyy_admin_registry_sigma.yml
Description
Detects potential registry activity of Ammyy Admin RMM tool
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/ammyy_admin_network_sigma.yml
Description
Detects potential network activity of Ammyy Admin RMM tool
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/ammyy_admin_files_sigma.yml
Description
Detects potential files activity of Ammyy Admin RMM tool
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/ammyy_admin_processes_sigma.yml
Description
Detects potential processes activity of Ammyy Admin RMM tool

References

Acknowledgements

Person
Kostas
Handle
@kostastsale