🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 11c21d873335c6d7e8a4a349716e5bd34f25fcd0353e296771c2765c8a3bc66c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Amadey


Vendor detections: 19


Intelligence 19 IOCs YARA 4 File information Comments

SHA256 hash: 11c21d873335c6d7e8a4a349716e5bd34f25fcd0353e296771c2765c8a3bc66c
SHA3-384 hash: 43a8d674b0a6e6ca2d5850bf982484e24bbfcbeb22a70817cd8035cf0ff8c73bbd9b1bda68b4bebd53a7f67d6fc50074
SHA1 hash: f487603fa26d132f64f488fbd81e075416bd9836
MD5 hash: 14503ecfabad1a1fc7eb044104b2a07c
humanhash: hot-delaware-alaska-mango
File name:ec2n7q9z58.exe
Download: download sample
Signature Amadey
File size:909'824 bytes
First seen:2025-09-21 10:24:43 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'239 x AgentTesla, 20'491 x Formbook, 12'372 x SnakeKeylogger)
ssdeep 24576:B/TiVdBHxSrVCoLnbUxvhgXTsiIaYLM7A8R+lrEAE:OgrkoMpksiIPAfR2v
Threatray 1'526 similar samples on MalwareBazaar
TLSH T1DB150141335BDA02E5F25FF44870C3B117B8BD4EA925D2065EFA6CEB7C35B00AA85366
TrID 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
10.2% (.EXE) Win64 Executable (generic) (10522/11/4)
6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.3% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
Reporter aachum
Tags:1b2025 Amadey dropped-by-Vidar exe


Avatar
iamaachum
Amadey Botnet: 1b2025
Amadey C2:
http://microsoft-telemetry.cc
http://xboxtelemetry-defender.cc

Intelligence


File Origin
# of uploads :
1
# of downloads :
204
Origin country :
ES ES
Vendor Threat Intelligence
Malware family:
ID:
1
File name:
ec2n7q9z58.exe
Verdict:
Malicious activity
Analysis date:
2025-09-21 10:26:35 UTC
Tags:
auto-drop amadey botnet stealer rdp

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
96.5%
Tags:
phishing autorun
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Restart of the analyzed sample
Creating a file
Сreating synchronization primitives
Searching for synchronization primitives
Creating a file in the %temp% subdirectories
Creating a process from a recently created file
Creating a process with a hidden window
DNS request
Connection attempt to an infection source
Connection attempt
Sending an HTTP POST request
Unauthorized injection to a recently created process
Unauthorized injection to a recently created process by context flags manipulation
Query of malicious DNS domain
Enabling autorun by creating a file
Sending an HTTP POST request to an infection source
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
amadey amadey base64 bitmap lolbin msbuild obfuscated packed packed reconnaissance regsvcs rezer0 roboski schtasks stego vbc vbnet
Verdict:
Malicious
File Type:
exe x32
First seen:
2025-09-19T00:14:00Z UTC
Last seen:
2025-09-19T00:14:00Z UTC
Hits:
~100
Result
Threat name:
n/a
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
Antivirus detection for URL or domain
Contains functionality to inject code into remote processes
Contains functionality to start a terminal service
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected AntiVM3
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1781476 Sample: ec2n7q9z58.exe Startdate: 21/09/2025 Architecture: WINDOWS Score: 100 49 xboxtelemetry-defender.cc 2->49 51 microsoft-telemetry.at 2->51 53 microsoft-telemetry.cc 2->53 59 Suricata IDS alerts for network traffic 2->59 61 Antivirus detection for URL or domain 2->61 63 Multi AV Scanner detection for submitted file 2->63 65 5 other signatures 2->65 9 ec2n7q9z58.exe 3 2->9         started        13 Srfuhxm.exe 3 2->13         started        15 Srfuhxm.exe 2->15         started        17 3 other processes 2->17 signatures3 process4 file5 47 C:\Users\user\AppData\...\ec2n7q9z58.exe.log, ASCII 9->47 dropped 71 Contains functionality to start a terminal service 9->71 73 Contains functionality to inject code into remote processes 9->73 75 Injects a PE file into a foreign processes 9->75 19 ec2n7q9z58.exe 5 9->19         started        77 Multi AV Scanner detection for dropped file 13->77 23 Srfuhxm.exe 12 13->23         started        26 Srfuhxm.exe 15->26         started        28 Srfuhxm.exe 15->28         started        30 Srfuhxm.exe 17->30         started        32 Srfuhxm.exe 17->32         started        34 Srfuhxm.exe 17->34         started        36 2 other processes 17->36 signatures6 process7 dnsIp8 43 C:\Users\user\AppData\Local\...\Srfuhxm.exe, PE32 19->43 dropped 45 C:\Users\user\...\Srfuhxm.exe:Zone.Identifier, ASCII 19->45 dropped 67 Contains functionality to start a terminal service 19->67 38 Srfuhxm.exe 2 19->38         started        55 xboxtelemetry-defender.cc 52.27.79.221, 49716, 49720, 49725 AMAZON-02US United States 23->55 57 microsoft-telemetry.at 23.94.252.8, 49714, 49715, 49718 AS-COLOCROSSINGUS United States 23->57 file9 signatures10 process11 signatures12 69 Contains functionality to start a terminal service 38->69 41 Srfuhxm.exe 38->41         started        process13
Verdict:
inconclusive
YARA:
10 match(es)
Tags:
.Net Executable Managed .NET PDB Path PE (Portable Executable) PE File Layout SOS: 0.44 Win 32 Exe x86
Threat name:
ByteCode-MSIL.Trojan.VIPKeylogger
Status:
Malicious
First seen:
2025-09-18 23:30:39 UTC
File Type:
PE (.Net Exe)
Extracted files:
9
AV detection:
29 of 38 (76.32%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:amadey botnet:1b2025 discovery trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Drops file in Windows directory
Suspicious use of SetThreadContext
Checks computer location settings
Executes dropped EXE
Amadey
Amadey family
Malware Config
C2 Extraction:
http://microsoft-telemetry.cc
http://xboxtelemetry-defender.cc
Verdict:
Suspicious
Tags:
n/a
YARA:
n/a
Unpacked files
SH256 hash:
11c21d873335c6d7e8a4a349716e5bd34f25fcd0353e296771c2765c8a3bc66c
MD5 hash:
14503ecfabad1a1fc7eb044104b2a07c
SHA1 hash:
f487603fa26d132f64f488fbd81e075416bd9836
SH256 hash:
1041b538ccbc7d66e59247ef7551cde9b6c282843541585e9190a8e2e3943b12
MD5 hash:
e870d1e8f3791ccc141f85f40fd2972b
SHA1 hash:
150919ee289cffa6feb40ab8261f620dd7e26aac
SH256 hash:
aa03c499b9b973e347fe32539415f0e900ad552206f4f3e12aec7c56943534bf
MD5 hash:
ce46219e7419d4629696617644cab7ef
SHA1 hash:
233170ddbc8f47e61787f830103fd12936f74fc7
Detections:
SUSP_OBF_NET_ConfuserEx_Name_Pattern_Jan24 SUSP_OBF_NET_Reactor_Indicators_Jan24
SH256 hash:
34e90a4e853a403550528858a409602e5471ad999748a7f53912730896476ebc
MD5 hash:
eb59600b981a6b29914b81ad3f3fe4df
SHA1 hash:
5349fe43328e2cf00474e0d56a73d239d3aadb1f
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_AllMal_Detector
Author:DiegoAnalytics
Description:CrossPlatform All Malwares Detector: Detect PE, ELF, Mach-O, scripts, archives; overlay, obfuscation, encryption, spoofing, hiding, high entropy, network communication
Rule name:NET
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Amadey

Executable exe 11c21d873335c6d7e8a4a349716e5bd34f25fcd0353e296771c2765c8a3bc66c

(this sample)

  
Dropped by
Vidar
  
Delivery method
Distributed via web download

Comments