Threat name:
Amadey, GCleaner, REMUS Stealer, Socks5S
Alert
Classification:
phis.troj.spyw.expl.evad
.NET source code contains potential unpacker
.NET source code contains very large strings
AI detected malicious page (phishing or scam)
Allocates memory in foreign processes
Bypasses PowerShell execution policy
C2 URLs / IPs found in malware configuration
Changes security center settings (notifications, updates, antivirus, firewall)
Detected unpacking (changes PE section rights)
Detected unpacking (creates a PE file in dynamic memory)
Detected unpacking (overwrites its own PE header)
Found direct / indirect Syscall (likely to bypass EDR)
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious webpage
Malicious sample detected (through community Yara rule)
Modifies the context of a thread in another process (thread injection)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Performs DNS queries to domains with low reputation
Queries DNS domain through GetComputerNameExW (potential sandbox evasion)
Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sample uses string decryption to hide its real strings
Sigma detected: Silenttrinity Stager Msbuild Activity
Sigma detected: WScript or CScript Dropper
Suricata IDS alerts for network traffic
Suspicious execution chain found
Suspicious powershell command line found
Tries to detect sandboxes / dynamic malware analysis system (Installed program check)
Tries to detect sandboxes / dynamic malware analysis system (registry check)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect virtualization through RDTSC time measurements
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to steal Crypto Currency Wallets
Tries to steal from password manager
Tries to steal Mail credentials (via file / registry access)
Unusual module load detection (module proxying)
Uses known network protocols on non-standard ports
Uses the Windows Restart Manager Abuse for Browser Credential File unlocking
Verifies if a H.264 Video Encoder exists (likely to detect the VM)
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
WScript reads language and country specific registry keys (likely country aware script)
Wscript starts Powershell (via cmd or directly)
Yara detected Amadeys Clipper DLL
Yara detected REMUS Stealer
Yara detected Socks5Systemz
Yara detected Vidar stealer
behaviorgraph
top1
dnsIp2
2
Behavior Graph
ID:
1963653
Sample:
Setup.exe
Startdate:
25/08/2026
Architecture:
WINDOWS
Score:
100
132
config.ridgecanvas.xyz
2->132
134
45.91.200.135
PODAONLV
Netherlands
2->134
136
24 other IPs or domains
2->136
170
Suricata IDS alerts
for network traffic
2->170
172
Found malware configuration
2->172
174
Malicious sample detected
(through community Yara
rule)
2->174
178
22 other signatures
2->178
12
Setup.exe
3
9
2->12
started
16
svchost.exe
2->16
started
18
svchost.exe
2->18
started
21
9 other processes
2->21
signatures3
176
Performs DNS queries
to domains with low
reputation
132->176
process4
dnsIp5
126
C:\Users\user\Desktop\appFile.exe, PE32+
12->126
dropped
128
C:\Users\user\Desktop\ae_mixtwo.exe, PE32
12->128
dropped
130
C:\Users\user\Desktop\OpenLink.ps1, ASCII
12->130
dropped
248
Drops large PE files
12->248
23
ae_mixtwo.exe
10
12->23
started
27
appFile.exe
12->27
started
29
wscript.exe
12->29
started
250
Changes security center
settings (notifications,
updates, antivirus,
firewall)
16->250
31
MpCmdRun.exe
16->31
started
138
127.0.0.1
unknown
unknown
18->138
33
conhost.exe
21->33
started
35
conhost.exe
21->35
started
file6
signatures7
process8
file9
122
C:\Users\user\AppData\Local\Temp\...\re21.exe, PE32+
23->122
dropped
224
Multi AV Scanner detection
for dropped file
23->224
226
Writes to foreign memory
regions
23->226
228
Allocates memory in
foreign processes
23->228
230
Injects a PE file into
a foreign processes
23->230
37
MSBuild.exe
33
23->37
started
42
re21.exe
3
23->42
started
232
Detected unpacking (creates
a PE file in dynamic
memory)
27->232
234
Queries sensitive video
device information (via
WMI, Win32_VideoController,
often done to detect
virtual machines)
27->234
236
Tries to steal Mail
credentials (via file
/ registry access)
27->236
244
7 other signatures
27->244
238
Suspicious powershell
command line found
29->238
240
Wscript starts Powershell
(via cmd or directly)
29->240
242
Bypasses PowerShell
execution policy
29->242
246
3 other signatures
29->246
44
powershell.exe
29->44
started
46
conhost.exe
31->46
started
signatures10
process11
dnsIp12
154
91.92.242.236, 49713, 80
OMEGATECH-ASSC
Netherlands
37->154
156
drive.usercontent.google.com
142.250.217.225, 443, 49711
GOOGLE-GoogleLLCUS
United States
37->156
114
C:\Users\user\AppData\...\uQ1XfeLlH8.exe, PE32
37->114
dropped
116
C:\Users\user\AppData\...\eIwb6Jr8sVT.exe, PE32+
37->116
dropped
118
C:\Users\user\AppData\...\RsKzAiMg5xQ7U.exe, PE32
37->118
dropped
120
7 other malicious files
37->120
dropped
214
Unusual module load
detection (module proxying)
37->214
48
RsKzAiMg5xQ7U.exe
37->48
started
51
HB7jMQYAiS.exe
37->51
started
55
SNrLE8Ks0qR.exe
37->55
started
63
5 other processes
37->63
216
Multi AV Scanner detection
for dropped file
42->216
218
Writes to foreign memory
regions
42->218
220
Modifies the context
of a thread in another
process (thread injection)
42->220
222
Injects a PE file into
a foreign processes
42->222
57
MSBuild.exe
42->57
started
59
chrome.exe
44->59
started
61
conhost.exe
44->61
started
file13
signatures14
process15
dnsIp16
94
C:\Users\user\AppData\...\RsKzAiMg5xQ7U.tmp, PE32
48->94
dropped
65
RsKzAiMg5xQ7U.tmp
48->65
started
140
config.ridgecanvas.xyz
172.67.157.155
CLOUDFLARENET-CloudflareIncUS
Canada
51->140
180
Tries to harvest and
steal Putty / WinSCP
information (sessions,
passwords, etc)
51->180
182
Found many strings related
to Crypto-Wallets (likely
being stolen)
51->182
184
Tries to detect virtualization
through RDTSC time measurements
51->184
204
5 other signatures
51->204
68
HB7jMQYAiS.exe
51->68
started
71
HB7jMQYAiS.exe
51->71
started
142
jij.sm188dvlv.icu
104.21.62.229
CLOUDFLARENET-CloudflareIncUS
Canada
55->142
144
dev.epicgames.com.cdn.cloudflare.net
104.18.0.68
CLOUDFLARENET-CloudflareIncUS
Canada
55->144
186
Multi AV Scanner detection
for dropped file
55->186
188
Tries to harvest and
steal browser information
(history, passwords,
etc)
55->188
190
Uses the Windows Restart
Manager Abuse for Browser
Credential File unlocking
55->190
82
2 other processes
55->82
146
vexdico.shop
165.227.199.109, 49735, 8539
DIGITALOCEAN-ASN-DigitalOceanLLCUS
United States
57->146
192
Queries sensitive video
device information (via
WMI, Win32_VideoController,
often done to detect
virtual machines)
57->192
194
Unusual module load
detection (module proxying)
57->194
148
192.168.2.4, 443, 49706, 49707
unknown
unknown
59->148
150
192.168.2.6
unknown
unknown
59->150
152
192.168.2.9
unknown
unknown
59->152
73
chrome.exe
59->73
started
96
C:\Users\user\AppData\...\D6RTJ1nH0x.tmp, PE32
63->96
dropped
98
C:\Users\user\AppData\...\uQ1XfeLlH8.exe.log, ASCII
63->98
dropped
196
Tries to detect sandboxes
and other dynamic analysis
tools (process name
or module or function)
63->196
198
Writes to foreign memory
regions
63->198
200
Allocates memory in
foreign processes
63->200
202
Injects a PE file into
a foreign processes
63->202
76
D6RTJ1nH0x.tmp
63->76
started
78
MSBuild.exe
63->78
started
80
conhost.exe
63->80
started
84
2 other processes
63->84
file17
signatures18
process19
dnsIp20
100
C:\Users\user\AppData\Local\...\_shfoldr.dll, PE32
65->100
dropped
102
C:\Users\user\AppData\Local\...\_setup64.tmp, PE32+
65->102
dropped
104
C:\Users\user\AppData\Local\...\_iscrypt.dll, PE32
65->104
dropped
112
21 other malicious files
65->112
dropped
86
AdvDefragConsole.exe
65->86
started
206
Tries to harvest and
steal browser information
(history, passwords,
etc)
68->206
208
Found direct / indirect
Syscall (likely to bypass
EDR)
68->208
210
Tries to detect sandboxes
/ dynamic malware analysis
system (registry check)
68->210
164
pulse.quantumbytehub1.lol
104.21.57.57, 443, 49723, 49724
CLOUDFLARENET-CloudflareIncUS
Canada
73->164
166
www.google.com
142.251.150.119, 443, 49716, 49720
GOOGLE-GoogleLLCUS
United States
73->166
168
5 other IPs or domains
73->168
106
Chrome Cache Entry: 261, PDP-11
73->106
dropped
108
C:\Users\user\AppData\Local\...\_isdecmp.dll, PE32
76->108
dropped
212
Queries sensitive service
information (via WMI,
Win32_LogicalDisk, often
done to detect sandboxes)
76->212
110
C:\Users\user\AppData\Local\...\Bwale.exe, PE32
78->110
dropped
90
Bwale.exe
78->90
started
file21
signatures22
process23
dnsIp24
158
94.26.38.17
OMEGATECH-ASSC
Netherlands
86->158
160
196.251.121.77
Hero-TelecomsZA
Turkey
86->160
162
2 other IPs or domains
86->162
124
C:\ProgramData\...\AdvDefragConsole.exe, PE32
86->124
dropped
92
conhost.exe
90->92
started
file25
process26
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.