🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4fd488f73f9f3dcd5188faa8bf28a73c613b6e68de22f644b009cca1eeef36a7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Amadey


Vendor detections: 16


Intelligence 16 IOCs YARA 8 File information Comments

SHA256 hash: 4fd488f73f9f3dcd5188faa8bf28a73c613b6e68de22f644b009cca1eeef36a7
SHA3-384 hash: 5d510b5ba38c2a5c769de22b6a820252f4c88048b31cf690b163ab8bc1ea0b33d4664509e50e2d14600825ed62aa775c
SHA1 hash: 093a1dbdad5a2d8200199570c44e39ace754d60d
MD5 hash: 8a1b9f32b1f964f3ba0b4081e5fe9fc4
humanhash: purple-may-batman-fillet
File name:8a1b9f32b1f964f3ba0b4081e5fe9fc4.exe
Download: download sample
Signature Amadey
File size:2'119'168 bytes
First seen:2025-02-09 16:34:54 UTC
Last seen:2025-02-09 17:55:36 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 2eabe9054cad5152567f0699947a2c5b (2'861 x LummaStealer, 1'312 x Stealc, 1'026 x Healer)
ssdeep 24576:M18s+LlMyvFgx0Cop6kU5WOV9zgI9MJgAufce3BiSRQxkaL8U4O+khkUDL0nW5OP:M1eYYARP91oSZlORuUDY4Ub4zb6mg
TLSH T193A512E84D563131F95A78BB420B8A9361296A729D97F30134CF93E9CDC22FE3660DC5
TrID 29.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
22.7% (.EXE) Win16 NE executable (generic) (5038/12/1)
20.3% (.EXE) Win32 Executable (generic) (4504/4/1)
9.1% (.EXE) OS/2 Executable (generic) (2029/13)
9.0% (.EXE) Generic Win/DOS Executable (2002/3)
Magika pebin
Reporter abuse_ch
Tags:Amadey exe

Intelligence


File Origin
# of uploads :
2
# of downloads :
494
Origin country :
NL NL
Vendor Threat Intelligence
Malware family:
ID:
1
File name:
8a1b9f32b1f964f3ba0b4081e5fe9fc4.exe
Verdict:
Malicious activity
Analysis date:
2025-02-09 16:40:18 UTC
Tags:
amadey botnet stealer loader themida auto redline lumma exfiltration lefthook fody gcleaner cryptbot

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.9%
Tags:
autorun spam
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Сreating synchronization primitives
Searching for analyzing tools
Creating a file
Creating a window
Searching for synchronization primitives
Creating a file in the %temp% subdirectories
Creating a process from a recently created file
Creating a process with a hidden window
Connection attempt to an infection source
Enabling autorun by creating a file
Sending an HTTP POST request to an infection source
Result
Threat name:
Amadey, LummaC Stealer, PureLog Stealer,
Detection:
malicious
Classification:
spre.phis.troj.spyw.expl.evad
Score:
100 / 100
Signature
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code references suspicious native API functions
Allocates memory in foreign processes
Antivirus / Scanner detection for submitted sample
Attempt to bypass Chrome Application-Bound Encryption
C2 URLs / IPs found in malware configuration
Creates HTA files
Creates multiple autostart registry keys
Detected unpacking (changes PE section rights)
Drops script or batch files to the startup folder
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Found suspicious powershell code related to unpacking or dynamic code loading
Hides threads from debuggers
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Monitors registry run keys for changes
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file contains section with special chars
Powershell drops PE file
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Query firmware table information (likely to detect VMs)
Sample uses string decryption to hide its real strings
Sigma detected: Base64 Encoded PowerShell Command Detected
Sigma detected: Drops script at startup location
Sigma detected: Invoke-Obfuscation CLIP+ Launcher
Sigma detected: Invoke-Obfuscation VAR+ Launcher
Sigma detected: New RUN Key Pointing to Suspicious Folder
Sigma detected: PowerShell Base64 Encoded FromBase64String Cmdlet
Sigma detected: Powershell download and execute file
Sigma detected: Powershell download and load assembly
Sigma detected: Powershell download payload from hardcoded c2 list
Sigma detected: PowerShell DownloadFile
Sigma detected: Powerup Write Hijack DLL
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Suspicious MSHTA Child Process
Sigma detected: Suspicious Script Execution From Temp Folder
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Tries to detect process monitoring tools (Task Manager, Process Explorer etc.)
Tries to detect sandboxes / dynamic malware analysis system (registry check)
Tries to detect sandboxes and other dynamic analysis tools (window names)
Tries to detect virtualization through RDTSC time measurements
Tries to download and execute files (via powershell)
Tries to evade debugger and weak emulator (self modifying code)
Tries to harvest and steal Bitcoin Wallet information
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to steal Crypto Currency Wallets
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
Wscript starts Powershell (via cmd or directly)
Yara detected Amadey
Yara detected Amadeys stealer DLL
Yara detected LummaC Stealer
Yara detected obfuscated html page
Yara detected Powershell decode and execute
Yara detected Powershell download and execute
Yara detected PureLog Stealer
Yara detected RedLine Stealer
Yara detected UAC Bypass using CMSTP
Yara detected Vidar stealer
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1610557 Sample: E41ACurBrc.exe Startdate: 09/02/2025 Architecture: WINDOWS Score: 100 206 Found malware configuration 2->206 208 Malicious sample detected (through community Yara rule) 2->208 210 Antivirus / Scanner detection for submitted sample 2->210 212 35 other signatures 2->212 12 E41ACurBrc.exe 5 2->12         started        16 msedge.exe 2->16         started        18 skotes.exe 2->18         started        20 5 other processes 2->20 process3 dnsIp4 140 C:\Users\user\AppData\Local\...\skotes.exe, PE32 12->140 dropped 142 C:\Users\user\...\skotes.exe:Zone.Identifier, ASCII 12->142 dropped 264 Detected unpacking (changes PE section rights) 12->264 266 Tries to evade debugger and weak emulator (self modifying code) 12->266 268 Tries to detect virtualization through RDTSC time measurements 12->268 23 skotes.exe 6 112 12->23         started        28 MSBuild.exe 12->28         started        30 MSBuild.exe 12->30         started        270 Suspicious powershell command line found 16->270 272 Tries to download and execute files (via powershell) 16->272 274 Maps a DLL or memory area into another process 16->274 32 msedge.exe 16->32         started        276 Hides threads from debuggers 18->276 278 Tries to detect sandboxes / dynamic malware analysis system (registry check) 18->278 280 Tries to detect process monitoring tools (Task Manager, Process Explorer etc.) 18->280 160 184.28.90.27 AKAMAI-ASUS United States 20->160 162 127.0.0.1 unknown unknown 20->162 282 Wscript starts Powershell (via cmd or directly) 20->282 34 powershell.exe 20->34         started        36 conhost.exe 20->36         started        38 cmd.exe 20->38         started        40 msedge.exe 20->40         started        file5 signatures6 process7 dnsIp8 172 185.215.113.16 WHOLESALECONNECTIONSNL Portugal 23->172 174 185.215.113.43 WHOLESALECONNECTIONSNL Portugal 23->174 176 185.215.113.97 WHOLESALECONNECTIONSNL Portugal 23->176 130 C:\Users\user\AppData\Local\...\Fe36XBk.exe, PE32 23->130 dropped 132 C:\Users\user\AppData\Local\...\dDFw6mJ.exe, PE32+ 23->132 dropped 134 C:\Users\user\AppData\...\fb68be4b9d.exe, PE32 23->134 dropped 138 48 other malicious files 23->138 dropped 224 Detected unpacking (changes PE section rights) 23->224 226 Tries to detect sandboxes and other dynamic analysis tools (window names) 23->226 228 Creates multiple autostart registry keys 23->228 240 4 other signatures 23->240 42 dDFw6mJ.exe 23->42         started        45 dDFw6mJ.exe 1 3 23->45         started        48 powershell.exe 23->48         started        59 13 other processes 23->59 182 2 other IPs or domains 28->182 230 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 28->230 232 Tries to steal Crypto Currency Wallets 28->232 234 Tries to harvest and steal Bitcoin Wallet information 28->234 50 msedge.exe 28->50         started        52 chrome.exe 28->52         started        55 msedge.exe 28->55         started        236 Attempt to bypass Chrome Application-Bound Encryption 30->236 184 29 other IPs or domains 32->184 136 C:\Users\user\AppData\Local\...\Cookies, SQLite 32->136 dropped 178 67.195.204.74 YAHOO-3US United States 34->178 180 52.101.8.49 MICROSOFT-CORP-MSN-AS-BLOCKUS United States 34->180 238 Suspicious powershell command line found 34->238 57 powershell.exe 34->57         started        file9 signatures10 process11 dnsIp12 242 Creates multiple autostart registry keys 42->242 61 cmd.exe 42->61         started        144 C:\Users\user\AppData\...\67a27a89a5061.vbs, ASCII 45->144 dropped 244 Multi AV Scanner detection for dropped file 45->244 63 cmd.exe 3 2 45->63         started        146 C:\Users\user\AppData\...\MyPayload.bat, DOS 48->146 dropped 148 C:\Users\user\AppData\Local\Temp\...\bs.bat, DOS 48->148 dropped 246 Suspicious powershell command line found 48->246 248 Drops script or batch files to the startup folder 48->248 250 Found many strings related to Crypto-Wallets (likely being stolen) 48->250 260 3 other signatures 48->260 66 cmd.exe 48->66         started        68 conhost.exe 48->68         started        252 Monitors registry run keys for changes 50->252 70 msedge.exe 50->70         started        164 239.255.255.250 unknown Reserved 52->164 72 chrome.exe 52->72         started        75 msedge.exe 55->75         started        166 147.45.198.154 FREE-NET-ASFREEnetEU Russian Federation 59->166 168 104.21.0.135 CLOUDFLARENETUS United States 59->168 170 3 other IPs or domains 59->170 150 C:\Users\user\AppData\Local\...\tmpA926.tmp, PE32 59->150 dropped 152 C:\Users\user\AppData\Local\...\Ioq4KWIxq.hta, HTML 59->152 dropped 254 Detected unpacking (changes PE section rights) 59->254 256 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 59->256 258 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 59->258 262 12 other signatures 59->262 77 mshta.exe 59->77         started        79 4 other processes 59->79 file13 signatures14 process15 dnsIp16 81 wscript.exe 61->81         started        84 conhost.exe 61->84         started        292 Wscript starts Powershell (via cmd or directly) 63->292 86 wscript.exe 1 63->86         started        88 conhost.exe 63->88         started        90 powershell.exe 66->90         started        93 conhost.exe 66->93         started        95 cmd.exe 66->95         started        186 142.250.110.84 GOOGLEUS United States 72->186 188 142.250.186.110 GOOGLEUS United States 72->188 190 7 other IPs or domains 72->190 294 Suspicious powershell command line found 77->294 296 Tries to download and execute files (via powershell) 77->296 97 powershell.exe 77->97         started        100 conhost.exe 79->100         started        signatures17 process18 dnsIp19 198 Suspicious powershell command line found 81->198 200 Wscript starts Powershell (via cmd or directly) 81->200 102 powershell.exe 81->102         started        202 Windows Scripting host queries suspicious COM object (likely to drop second stage) 86->202 204 Suspicious execution chain found 86->204 105 powershell.exe 7 86->105         started        192 98.136.96.91 YAHOO-NE1US United States 90->192 194 67.195.204.73 YAHOO-3US United States 90->194 196 10 other IPs or domains 90->196 107 powershell.exe 90->107         started        128 TempBUPETD9XT8YSBG2AR1GMSXCECQNWBQXK.EXE, PE32 97->128 dropped 109 conhost.exe 97->109         started        111 Conhost.exe 97->111         started        113 Conhost.exe 100->113         started        file20 signatures21 process22 signatures23 220 Suspicious powershell command line found 102->220 115 powershell.exe 102->115         started        119 conhost.exe 102->119         started        222 Found suspicious powershell code related to unpacking or dynamic code loading 105->222 121 powershell.exe 14 23 105->121         started        123 conhost.exe 105->123         started        process24 dnsIp25 154 185.166.143.48 AMAZON-02US Germany 115->154 214 Writes to foreign memory regions 115->214 216 Injects a PE file into a foreign processes 115->216 218 Loading BitLocker PowerShell Module 115->218 125 MSBuild.exe 115->125         started        156 185.199.109.153 FASTLYUS Netherlands 121->156 158 62.60.226.64 ASLINE-AS-APASLINELIMITEDHK Iran (ISLAMIC Republic Of) 121->158 signatures26 process27 signatures28 284 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 125->284 286 Tries to harvest and steal ftp login credentials 125->286 288 Tries to harvest and steal browser information (history, passwords, etc) 125->288 290 2 other signatures 125->290
Threat name:
Win32.Trojan.LummaStealer
Status:
Malicious
First seen:
2025-02-09 16:35:11 UTC
File Type:
PE (Exe)
Extracted files:
2
AV detection:
23 of 24 (95.83%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
Similar samples:
Result
Malware family:
Score:
  10/10
Tags:
family:amadey botnet:9c9aa5 defense_evasion discovery execution trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: PowerShell
Enumerates physical storage devices
System Location Discovery: System Language Discovery
System Network Configuration Discovery: Internet Connection Discovery
Drops file in Windows directory
Suspicious use of NtSetInformationThreadHideFromDebugger
Checks BIOS information in registry
Checks computer location settings
Executes dropped EXE
Identifies Wine through registry keys
Loads dropped DLL
Downloads MZ/PE file
Identifies VirtualBox via ACPI registry values (likely anti-VM)
Amadey
Amadey family
Malware Config
C2 Extraction:
http://185.215.113.43
Verdict:
Malicious
Tags:
redline win32_amadey
YARA:
n/a
Unpacked files
SH256 hash:
4fd488f73f9f3dcd5188faa8bf28a73c613b6e68de22f644b009cca1eeef36a7
MD5 hash:
8a1b9f32b1f964f3ba0b4081e5fe9fc4
SHA1 hash:
093a1dbdad5a2d8200199570c44e39ace754d60d
SH256 hash:
60e072f457a34400c07e63981eb24ae641ebd94ddfb1d61ca7a9527eb9af9db2
MD5 hash:
aa246667ea319c377eafd2883794acad
SHA1 hash:
259a0b34ce5b52839fb727fb150e1d74444c5964
Detections:
Amadey win_amadey
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Amadey
Author:kevoreilly
Description:Amadey Payload
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:pe_detect_tls_callbacks
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques
Rule name:Windows_Generic_Threat_1f2e969c
Author:Elastic Security
Rule name:win_amadey_a9f4
Author:Johannes Bader
Description:matches unpacked Amadey samples

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
CHECK_NXMissing Non-Executable Memory Protectioncritical

Comments