RMM
Ammyy Admin
Ammyy Admin is a remote monitoring and management (RMM) tool. Ammyy admin has been used by scammers to gain remote access to victims' computers. The tool is legitimate and is used by IT professionals for remote management. However, it has been abused by scammers to gain unauthorized access to victims' computers. The tool is free for personal use, but a license is required for commercial use. The tool allows for remote desktop control, file transfer, voice chat, and more. The tool is available for Windows only. will be added as it becomes available.
Tool overview
- Category
- RMM
- Research authors
- @kostsatsale
- Created
- 2024-05-08
- Last modified
- 2024-05-08
- Privileges
- Curent User
- Free / availability
- Yes/1 active session at a time
- Verification required
- None
- Supported platforms
Windows
Capabilities
Known vulnerabilities
- CVE-2013-5582
Executables & installation paths
- Filename
- AA_v3.exe
- OriginalFileName
- Not recorded
- Description
- Ammyy Admin
Installation paths
C:\\ProgramData\\AMMYY\\*
AMMYY_Admin.exe
aa_v*.exe
C:\Users\*\Downloads\AMMYY_Admin.exe
*\AMMYY_Admin.exe
FORENSIC EVIDENCE
Disk artifacts
- File
- %programdata%\\AMMYY\\access.log
- Description
- Ammyy Admin access log file. Contains information about the remote IP address, the time of connection, bytes recv/send, and the ID of the remote machine.
- OS
- Windows
- Example
- 20240805-22:20:45.962000 00000D98 - [0] PASSED authorization remoteId=XXXXXXXX; TCP by router 136.243.104.235:443
- 20240805-22:22:34.139000 00000710 - [1] FAILED authorization remoteId=XXXXXXXX; TCP by router 136.243.104.235:443
- 20240805-22:23:10.648000 00000D98 - [0] ENDED authorized session, bytes recv/send = 1164 / 115378
- File
- %Binary_path%\\AA_v3.log
- Description
- Ammyy Admin log file. Contains application related logs.
- OS
- Windows
- Example
- 20240805-22:19:52.455000 00001318 - ERROR: ERROR: 2 RLEvent::TryToOpen(Global\AANS_FvwjZ_CHI)
- 20240805-22:23:10.648000 00000D98 - ERROR: ERROR SetThreadDesktop(200) 170
FORENSIC EVIDENCE
Event log artifacts
- EventID
- 4688
- ProviderName
- Microsoft-Security-Auditing
- LogFile
- Security.evtx
- CommandLine
- rundll32.exe "C:\ProgramData\AMMYY\aa_nts.dll",run
- Description
- Execution of Ammyy Admin
- EventID
- 7045
- ProviderName
- Service Control Manager
- LogFile
- System.evtx
- ServiceName
- Ammyy Admin
- ImagePath
- C:\*\AA_v3.exe
- Description
- Ammyy Admin service installation event
FORENSIC EVIDENCE
Registry artifacts
- Path
- HKU\.DEFAULT\Software\Ammyy\Admin
- Key
- hr3
- Type
- Reg_Binary
- Description
- Writing the hr3 binary in the registry. The hr3 is likely used to store admin-related information.
- Path
- HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\AmmyyAdmin
- Description
- Ammyy Admin service allows AMMYY admin to run in safe mode.
FORENSIC EVIDENCE
Network artifacts
- Description
- Known remote domains and router IP addresses
- Domains
- ammyy.com
- *.ammyy.com
- Ports
- 5931
- 80
- 443
- 8080
- Description
- Known router IP addresses (TCP connections)
- Domains
- 136.243.104.235
- 136.243.104.242
- 136.243.18.122
- Ports
- 443
Detections
- Sigma
- https://github.com/tsale/Sigma_rules/blob/main/Threat%20Hunting%20Queries/ammyy_admin.yml
- Name
- Detecting Ammy Admin RMM Agent Execution
- Description
- Detects the execution of the Ammy Admin RMM agent for remote management.
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/ammyy_admin_registry_sigma.yml
- Description
- Detects potential registry activity of Ammyy Admin RMM tool
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/ammyy_admin_network_sigma.yml
- Description
- Detects potential network activity of Ammyy Admin RMM tool
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/ammyy_admin_files_sigma.yml
- Description
- Detects potential files activity of Ammyy Admin RMM tool
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/ammyy_admin_processes_sigma.yml
- Description
- Detects potential processes activity of Ammyy Admin RMM tool
References
Acknowledgements
- Person
- Kostas
- Handle
- @kostastsale