Active malware distribution server at 91.92.242.236 (OMEGATECH bulletproof hosting, AS202412). Freshly compiled PE32+ injection module with zero AV detections at time of discovery. Full static analysis, IOC extraction, and infrastructure attribution.
Payload confirmed offline. /sava/build2_sava.exe returns HTTP 404. Root path also 404. Server 91.92.242.236 remains reachable (ICMP live, ~125ms) but all malicious content removed — open directory listing gone. Amadey dropper distribution endpoint neutralised. Victim machines can no longer pull the binary from this infrastructure.
On 2026-08-16 at approximately 12:40 UTC, a freshly compiled PE32+ Windows binary was discovered actively served from IP address 91.92.242.236 — hosted on bulletproof hosting provider OMEGATECH LTD (AS202412, Seychelles). The binary is a module of the Amadey botnet, a commercially available pay-per-install malware dropper widely used to distribute ransomware, information stealers, and banking trojans.
The sample was compiled only minutes before discovery, which explains why it registered zero detections on VirusTotal (0/72 AV engines). This is a deliberate evasion tactic: fresh compilation bypasses all signature-based detection. The server runs nginx/1.24.0 on Ubuntu with a completely open directory listing, serving the binary with no authentication and no rate limiting.
OMEGATECH LTD is a documented bulletproof hosting provider known to host 67+ command-and-control servers across 16 malware families. They operate as a Seychelles shell company with the real operation in Turkey (MGN TEKNOLOJI). Their upstream transit is Pfcloud UG and aurologic GmbH, both registered in Germany.
Exported Functions (Injection Interface):
Win32 API Import Map — What This Binary Can Do:
Self-Deletion Mechanism (extracted from strings):
| Type | Value | Context |
|---|---|---|
| IPv4 | 91.92.242.236 | Active malware distribution server |
| ASN | AS202412 | OMEGATECH bulletproof hosting range |
| SHA-256 | 0d581dac21e6140f342a435a92a52e372cea57bfb75cf41cc135b8ff39b875fd | client64.bin — Amadey injection module |
| MD5 | 0d93141625dda947333cdad23f13b619 | client64.bin |
| Filename | client64.bin | PE32+ x86-64 GUI, 219 KB, compiled 2026-08-16 12:40 UTC |
| Export | InjectApcRoutine | APC-based process injection entry point |
| Export | InjectNormalRoutine | CreateRemoteThread injection entry point |
| String | cmd.exe /c ping 127.0.0.1 -n 3 > nul && del /f /q | Self-deletion mechanism |
| Abuse Contact | abuse@omegatech.sc | Hosting provider (bulletproof — low efficacy) |
| Registrar Abuse | registrar-abuse@cloudflare.com | Domain registrar |
Reported to incidents@cert.be. CERT.be is the correct Belgian authority for malware infrastructure — they handle cross-border threat intel, coordinate with international CERTs, and escalate to FCCU only when a confirmed Belgian victim is identified. Submitted: full IOC list, binary hash, download URL, ASN attribution, MITRE ATT&CK mapping.
Submitted to abuse@cloudflare.com. Requested suspension of malware delivery domains and IP reputation update for AS202412. Cloudflare's abuse team coordinates with upstream ASN operators for bulletproof hosting takedowns.
Reported to ec3@europol.europa.eu. AS202412 (OMEGATECH) is documented bulletproof hosting with 16+ malware families across 67+ C2 servers — a cross-border organized infrastructure report is the right EC3 scope. Submitted full IOC table and PE static analysis.
Headless browser screenshot of 91.92.242.236 (C2 server) captured during investigation. The server returns a minimal response — consistent with a malware C2 that only serves specific file paths rather than a browsable index. The malware binary at /sava/build2_sava.exe was confirmed during investigation (now 404 — binary removed or rotated).
Server returns minimal HTTP response — C2 servers do not serve web pages. Confirmed live malware distribution during investigation.