Threat name:
Amadey, LummaC Stealer, PureLog Stealer,
Alert
Classification:
spre.phis.troj.spyw.expl.evad
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code references suspicious native API functions
Allocates memory in foreign processes
Antivirus / Scanner detection for submitted sample
Attempt to bypass Chrome Application-Bound Encryption
C2 URLs / IPs found in malware configuration
Creates multiple autostart registry keys
Detected unpacking (changes PE section rights)
Drops script or batch files to the startup folder
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Found suspicious powershell code related to unpacking or dynamic code loading
Hides threads from debuggers
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Monitors registry run keys for changes
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file contains section with special chars
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Query firmware table information (likely to detect VMs)
Sample uses string decryption to hide its real strings
Sigma detected: Base64 Encoded PowerShell Command Detected
Sigma detected: Drops script at startup location
Sigma detected: Invoke-Obfuscation CLIP+ Launcher
Sigma detected: Invoke-Obfuscation VAR+ Launcher
Sigma detected: New RUN Key Pointing to Suspicious Folder
Sigma detected: PowerShell Base64 Encoded FromBase64String Cmdlet
Sigma detected: Powershell download and execute file
Sigma detected: Powershell download and load assembly
Sigma detected: Powershell download payload from hardcoded c2 list
Sigma detected: PowerShell DownloadFile
Sigma detected: Powerup Write Hijack DLL
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Suspicious MSHTA Child Process
Sigma detected: Suspicious Script Execution From Temp Folder
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Tries to detect process monitoring tools (Task Manager, Process Explorer etc.)
Tries to detect sandboxes / dynamic malware analysis system (registry check)
Tries to detect sandboxes and other dynamic analysis tools (window names)
Tries to detect virtualization through RDTSC time measurements
Tries to download and execute files (via powershell)
Tries to evade debugger and weak emulator (self modifying code)
Tries to harvest and steal Bitcoin Wallet information
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to steal Crypto Currency Wallets
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
Wscript starts Powershell (via cmd or directly)
Yara detected Amadeys stealer DLL
Yara detected LummaC Stealer
Yara detected obfuscated html page
Yara detected Powershell decode and execute
Yara detected Powershell download and execute
Yara detected PureLog Stealer
Yara detected RedLine Stealer
Yara detected UAC Bypass using CMSTP
Yara detected Vidar stealer
behaviorgraph
top1
signatures2
2
Behavior Graph
ID:
1610557
Sample:
E41ACurBrc.exe
Startdate:
09/02/2025
Architecture:
WINDOWS
Score:
100
206
Found malware configuration
2->206
208
Malicious sample detected
(through community Yara
rule)
2->208
210
Antivirus / Scanner
detection for submitted
sample
2->210
212
35 other signatures
2->212
12
E41ACurBrc.exe
5
2->12
started
16
msedge.exe
2->16
started
18
skotes.exe
2->18
started
20
5 other processes
2->20
process3
dnsIp4
140
C:\Users\user\AppData\Local\...\skotes.exe, PE32
12->140
dropped
142
C:\Users\user\...\skotes.exe:Zone.Identifier, ASCII
12->142
dropped
264
Detected unpacking (changes
PE section rights)
12->264
266
Tries to evade debugger
and weak emulator (self
modifying code)
12->266
268
Tries to detect virtualization
through RDTSC time measurements
12->268
23
skotes.exe
6
112
12->23
started
28
MSBuild.exe
12->28
started
30
MSBuild.exe
12->30
started
270
Suspicious powershell
command line found
16->270
272
Tries to download and
execute files (via powershell)
16->272
274
Maps a DLL or memory
area into another process
16->274
32
msedge.exe
16->32
started
276
Hides threads from debuggers
18->276
278
Tries to detect sandboxes
/ dynamic malware analysis
system (registry check)
18->278
280
Tries to detect process
monitoring tools (Task
Manager, Process Explorer
etc.)
18->280
160
184.28.90.27
AKAMAI-ASUS
United States
20->160
162
127.0.0.1
unknown
unknown
20->162
282
Wscript starts Powershell
(via cmd or directly)
20->282
34
powershell.exe
20->34
started
36
conhost.exe
20->36
started
38
cmd.exe
20->38
started
40
msedge.exe
20->40
started
file5
signatures6
process7
dnsIp8
172
185.215.113.16
WHOLESALECONNECTIONSNL
Portugal
23->172
174
185.215.113.43
WHOLESALECONNECTIONSNL
Portugal
23->174
176
185.215.113.97
WHOLESALECONNECTIONSNL
Portugal
23->176
130
C:\Users\user\AppData\Local\...\Fe36XBk.exe, PE32
23->130
dropped
132
C:\Users\user\AppData\Local\...\dDFw6mJ.exe, PE32+
23->132
dropped
134
C:\Users\user\AppData\...\fb68be4b9d.exe, PE32
23->134
dropped
138
48 other malicious files
23->138
dropped
224
Detected unpacking (changes
PE section rights)
23->224
226
Tries to detect sandboxes
and other dynamic analysis
tools (window names)
23->226
228
Creates multiple autostart
registry keys
23->228
240
4 other signatures
23->240
42
dDFw6mJ.exe
23->42
started
45
dDFw6mJ.exe
1
3
23->45
started
48
powershell.exe
23->48
started
59
13 other processes
23->59
182
2 other IPs or domains
28->182
230
Tries to harvest and
steal Putty / WinSCP
information (sessions,
passwords, etc)
28->230
232
Tries to steal Crypto
Currency Wallets
28->232
234
Tries to harvest and
steal Bitcoin Wallet
information
28->234
50
msedge.exe
28->50
started
52
chrome.exe
28->52
started
55
msedge.exe
28->55
started
236
Attempt to bypass Chrome
Application-Bound Encryption
30->236
184
29 other IPs or domains
32->184
136
C:\Users\user\AppData\Local\...\Cookies, SQLite
32->136
dropped
178
67.195.204.74
YAHOO-3US
United States
34->178
180
52.101.8.49
MICROSOFT-CORP-MSN-AS-BLOCKUS
United States
34->180
238
Suspicious powershell
command line found
34->238
57
powershell.exe
34->57
started
file9
signatures10
process11
dnsIp12
242
Creates multiple autostart
registry keys
42->242
61
cmd.exe
42->61
started
144
C:\Users\user\AppData\...\67a27a89a5061.vbs, ASCII
45->144
dropped
244
Multi AV Scanner detection
for dropped file
45->244
63
cmd.exe
3
2
45->63
started
146
C:\Users\user\AppData\...\MyPayload.bat, DOS
48->146
dropped
148
C:\Users\user\AppData\Local\Temp\...\bs.bat, DOS
48->148
dropped
246
Suspicious powershell
command line found
48->246
248
Drops script or batch
files to the startup
folder
48->248
250
Found many strings related
to Crypto-Wallets (likely
being stolen)
48->250
260
3 other signatures
48->260
66
cmd.exe
48->66
started
68
conhost.exe
48->68
started
252
Monitors registry run
keys for changes
50->252
70
msedge.exe
50->70
started
164
239.255.255.250
unknown
Reserved
52->164
72
chrome.exe
52->72
started
75
msedge.exe
55->75
started
166
147.45.198.154
FREE-NET-ASFREEnetEU
Russian Federation
59->166
168
104.21.0.135
CLOUDFLARENETUS
United States
59->168
170
3 other IPs or domains
59->170
150
C:\Users\user\AppData\Local\...\tmpA926.tmp, PE32
59->150
dropped
152
C:\Users\user\AppData\Local\...\Ioq4KWIxq.hta, HTML
59->152
dropped
254
Detected unpacking (changes
PE section rights)
59->254
256
Tries to harvest and
steal Putty / WinSCP
information (sessions,
passwords, etc)
59->256
258
Queries sensitive video
device information (via
WMI, Win32_VideoController,
often done to detect
virtual machines)
59->258
262
12 other signatures
59->262
77
mshta.exe
59->77
started
79
4 other processes
59->79
file13
signatures14
process15
dnsIp16
81
wscript.exe
61->81
started
84
conhost.exe
61->84
started
292
Wscript starts Powershell
(via cmd or directly)
63->292
86
wscript.exe
1
63->86
started
88
conhost.exe
63->88
started
90
powershell.exe
66->90
started
93
conhost.exe
66->93
started
95
cmd.exe
66->95
started
186
142.250.110.84
GOOGLEUS
United States
72->186
188
142.250.186.110
GOOGLEUS
United States
72->188
190
7 other IPs or domains
72->190
294
Suspicious powershell
command line found
77->294
296
Tries to download and
execute files (via powershell)
77->296
97
powershell.exe
77->97
started
100
conhost.exe
79->100
started
signatures17
process18
dnsIp19
198
Suspicious powershell
command line found
81->198
200
Wscript starts Powershell
(via cmd or directly)
81->200
102
powershell.exe
81->102
started
202
Windows Scripting host
queries suspicious COM
object (likely to drop
second stage)
86->202
204
Suspicious execution
chain found
86->204
105
powershell.exe
7
86->105
started
192
98.136.96.91
YAHOO-NE1US
United States
90->192
194
67.195.204.73
YAHOO-3US
United States
90->194
196
10 other IPs or domains
90->196
107
powershell.exe
90->107
started
128
TempBUPETD9XT8YSBG2AR1GMSXCECQNWBQXK.EXE, PE32
97->128
dropped
109
conhost.exe
97->109
started
111
Conhost.exe
97->111
started
113
Conhost.exe
100->113
started
file20
signatures21
process22
signatures23
220
Suspicious powershell
command line found
102->220
115
powershell.exe
102->115
started
119
conhost.exe
102->119
started
222
Found suspicious powershell
code related to unpacking
or dynamic code loading
105->222
121
powershell.exe
14
23
105->121
started
123
conhost.exe
105->123
started
process24
dnsIp25
154
185.166.143.48
AMAZON-02US
Germany
115->154
214
Writes to foreign memory
regions
115->214
216
Injects a PE file into
a foreign processes
115->216
218
Loading BitLocker PowerShell
Module
115->218
125
MSBuild.exe
115->125
started
156
185.199.109.153
FASTLYUS
Netherlands
121->156
158
62.60.226.64
ASLINE-AS-APASLINELIMITEDHK
Iran (ISLAMIC Republic Of)
121->158
signatures26
process27
signatures28
284
Tries to harvest and
steal Putty / WinSCP
information (sessions,
passwords, etc)
125->284
286
Tries to harvest and
steal ftp login credentials
125->286
288
Tries to harvest and
steal browser information
(history, passwords,
etc)
125->288
290
2 other signatures
125->290
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.