🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3db7347ca051fd3bf9bd0cb95e844b9e8b3dd5a4e5649e673c2b02293a5b22f7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Amadey


Vendor detections: 3


Intelligence 3 IOCs YARA 2 File information Comments

SHA256 hash: 3db7347ca051fd3bf9bd0cb95e844b9e8b3dd5a4e5649e673c2b02293a5b22f7
SHA3-384 hash: 6fed24be3e032b10f3ca5fb50e313e110b13be769304eec6f1e851975be48f9a1e75347aa99abe7953fba05bc56a9700
SHA1 hash: 571151f6226c1fdfa2bee4bb485c72a96071b3d5
MD5 hash: c33afcfae6644cbf7ba6aa4b3d6e130d
humanhash: william-zebra-salami-mexico
File name:F F M 6 5.zip
Download: download sample
Signature Amadey
File size:15'608'683 bytes
First seen:2025-03-29 22:39:40 UTC
Last seen:Never
File type: zip
MIME type:application/zip
Note:This file is a password protected archive. The password is: 2025
ssdeep 393216:Cf/UQHSxMdIrmIjuNVDWB1zq0dGXwGJCAWDwnIz4Gq:wMrXQWvjGI4Gq
TLSH T1F2F633671B792ACF988111E0A485EB0DA91652FF21C06E19F7FC810DB9602D8EEDF735
Magika zip
Reporter tcains1
Tags:Amadey file-pumped LummaStealer pw-2025 zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
US US
File Archive Information

This file archive contains 10 file(s), sorted by their relevance:

File name:Ronix Hub.txt
File size:107 bytes
SHA256 hash: efa079e2d60d28f49740e282c645a8c53793d78183464ded980f0f339affe1ac
MD5 hash: 9f62ceffbb55f6423c23cdc8e671f7bb
MIME type:text/plain
Signature Amadey
File name:Alchemy Hub.txt
File size:60 bytes
SHA256 hash: 9fdca0132580574fb6aff476846260ca2f58e8a70bea40470f5649d7fa92dcf8
MD5 hash: d5d6daf63721445c19d0f7e0a03445a8
MIME type:text/plain
Signature Amadey
File name:Lyth Hub.txt
File size:156 bytes
SHA256 hash: 74e9323439799175d9839ab7b6a8594f36e4bf2fe6b6b1e11794da1cdcde85f5
MD5 hash: f67f0f9b7d4cb6f20ebec9b284625bff
MIME type:text/plain
Signature Amadey
File name:config.vdf
File size:14'357 bytes
SHA256 hash: 9fce8b4ac41455418615f2785199f72d7fe6ce39d8cd9182027a752c4f26d04a
MD5 hash: bb23e26ed15c9951460513efdb0b7ac7
MIME type:text/plain
Signature Amadey
File name:Mod Menu Panel.exe
Pumped file This file is pumped. MalwareBazaar has de-pumped it.
File size:178'257'937 bytes
SHA256 hash: 0280468d03d05e98504a7dc4eb3b9d7f6f18f7bd0f2360e7902c0045a87dc3bd
MD5 hash: 6a21669da48bbd955ab188683161b2de
De-pumped file size:208'896 bytes (Vs. original size of 178'257'937 bytes)
De-pumped SHA256 hash: 782c7d77baad96cd72b6c3cbb8f9b18065d7f212db0ee7e9acf1b402cb58ad40
De-pumped MD5 hash: 63845cfff7147a1296142afa989a3b24
MIME type:application/x-dosexec
Signature Amadey
File name:Speed Hub X.txt
File size:115 bytes
SHA256 hash: d06051fd52392bc38b70a57e1efdcaca23c01bd9c356bcc3136ca1bdc7a62112
MD5 hash: cb1e84e476474691c91e58d028d32228
MIME type:text/plain
Signature Amadey
File name:cacert.pem
File size:2'740 bytes
SHA256 hash: 5513aa54afe134569e08b27aa61e60e888ab31d9e112f8c5881adbaecc817678
MD5 hash: 39f89143815797c4a41c62f30f137094
MIME type:text/plain
Signature Amadey
File name:Zenith Hub.txt
File size:104 bytes
SHA256 hash: 462f4f358cf80067b8819ad55601d7fd478c5fb937de47055090bb41c3344400
MD5 hash: 21dc121348612acd6cbda15e83578a2e
MIME type:text/plain
Signature Amadey
File name:ai.cfg
File size:44 bytes
SHA256 hash: db9ec7ae21d140904d44d6e6550c0c964e32ef11c055696b355835905c9c3a53
MD5 hash: 73ed0e22c8cc70ed93dfd0c1b8f81e19
MIME type:text/plain
Signature Amadey
File name:Client.config
File size:34'652'008 bytes
SHA256 hash: f9aae2ca83d60ae3a6e443d23c91672cda766f73003e4f3f0f99eec1f336d946
MD5 hash: 157bca5bfbab154797fbbe947946084f
MIME type:application/x-dosexec
Signature Amadey
Vendor Threat Intelligence
Result
Verdict:
Malicious
File Type:
ZIP File - Malicious
Behaviour
SuspiciousEmbeddedObjects detected
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Amadey

zip 3db7347ca051fd3bf9bd0cb95e844b9e8b3dd5a4e5649e673c2b02293a5b22f7

(this sample)

  
Delivery method
Distributed via web download

Comments