🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 59fcc56efd21db4b47a6b1fa44bfa63e0126bd4ae6579978263304cc7f32a84f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Amadey


Vendor detections: 6


Intelligence 6 IOCs YARA 13 File information Comments

SHA256 hash: 59fcc56efd21db4b47a6b1fa44bfa63e0126bd4ae6579978263304cc7f32a84f
SHA3-384 hash: 16293bc82321c2748b04b61e981c4150b2db00c7b7395bacd9bddc58be725e291dfae547c95f172f4e0480d42a222640
SHA1 hash: 6d82fdf2184e63aecbbb6db71b0ecbcefaa8098f
MD5 hash: 600a02961f25ea462d64809366641098
humanhash: fanta-sixteen-magnesium-lemon
File name:Amadey.zip
Download: download sample
Signature Amadey
File size:70'900'399 bytes
First seen:2025-07-15 17:31:41 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 1572864:jHcn6GG77MQ4lcnRwK0+uLT2h0X2hi2IAwnVEHx:An60kH0+wSh0GhizAzHx
TLSH T1B1F7339E06002F6ACA10C0F7AA9F3B7C3D1D07775695E7633D18A007D789E296825DEB
Magika zip
Reporter burger
Tags:Amadey bundled zip


Avatar
burger403
All files from hxxps://badabyms[.]site/
The password to the original .rar files is 2025

Intelligence


File Origin
# of uploads :
1
# of downloads :
52
Origin country :
NL NL
Vendor Threat Intelligence
Verdict:
Malicious
Score:
97.4%
Tags:
autorun emotet
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
anti-debug mingw overlay overlay packed
Gathering data
Threat name:
Win32.Infostealer.Tinba
Status:
Malicious
First seen:
2025-07-15 17:32:02 UTC
File Type:
Binary (Archive)
Extracted files:
1587
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:botnet_plaintext_c2
Author:cip
Description:Attempts to match at least some of the strings used in some botnet variants which use plaintext communication protocols.
Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:Detect_NSIS_Nullsoft_Installer
Author:Obscurity Labs LLC
Description:Detects NSIS installers by .ndata section + NSIS header string
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:Windows_Generic_Threat_e8abb835
Author:Elastic Security
Rule name:win_amadey_062025
Author:0x0d4y
Description:This rule detects intrinsic patterns of Amadey version 5.34.
Reference:https://0x0d4y.blog/amadey-targeted-analysis/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Amadey

zip 59fcc56efd21db4b47a6b1fa44bfa63e0126bd4ae6579978263304cc7f32a84f

(this sample)

  
Delivery method
Distributed via web download

Comments