🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5ad2cb58c77377f993aaa487843697b5aae8e475591f06503a9c9178e91c568a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Amadey


Vendor detections: 17


Intelligence 17 IOCs YARA 9 File information Comments

SHA256 hash: 5ad2cb58c77377f993aaa487843697b5aae8e475591f06503a9c9178e91c568a
SHA3-384 hash: b036cfe65068849a76152f07e6e7ec16e203de41b5377631bf475e201075482480a7746e8d0ac7c0e7c1eb90231ebfe1
SHA1 hash: 5cdcabe3fc73263422c8b89b256e3e40cdfdcff7
MD5 hash: bceb458a9aa5fa74da8a6a096e9542d3
humanhash: carolina-mike-seventeen-iowa
File name:tok.exe
Download: download sample
Signature Amadey
File size:435'638 bytes
First seen:2025-06-02 14:58:59 UTC
Last seen:2025-06-03 14:53:21 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 1e7280afbf80c2800b272220ce0718da (37 x Amadey, 2 x RedLineStealer, 1 x CredentialFlusher)
ssdeep 6144:YiUuGdolfFd313lcnGpPpnbJoHtbspmZfkCw3uWgGUS/T+WiU+9GTA/nw4AO2Y0U:YiUuGdolfFd1lGkpbCVkCweWgB7v9jV
TLSH T196946C217813C032D66291712FB9FFF585ADA8259B7109DB77C40F769A202E27A31F39
TrID 32.2% (.EXE) Win64 Executable (generic) (10522/11/4)
20.1% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
15.4% (.EXE) Win16 NE executable (generic) (5038/12/1)
13.7% (.EXE) Win32 Executable (generic) (4504/4/1)
6.2% (.EXE) OS/2 Executable (generic) (2029/13)
Magika pebin
Reporter Anonymous
Tags:Amadey exe

Intelligence


File Origin
# of uploads :
2
# of downloads :
527
Origin country :
NL NL
Vendor Threat Intelligence
Malware family:
ID:
1
File name:
https://cdn.discordapp.com/attachments/1375836241425072188/1375836310207467650/tok.exe?ex=6833cbaa&is=68327a2a&hm=3c3023ab511d42dfe05bdda6d2575376a91cb264753b5408914ab752beb5186b&
Verdict:
Malicious activity
Analysis date:
2025-05-25 13:22:15 UTC
Tags:
discord payload amadey botnet stealer loader telegram lumma python arch-exec rdp

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.9%
Tags:
vmdetect autorun emotet lien
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Сreating synchronization primitives
Creating a file
Creating a window
Searching for synchronization primitives
Creating a file in the %temp% subdirectories
Creating a process from a recently created file
Creating a process with a hidden window
Connection attempt to an infection source
Enabling autorun by creating a file
Sending an HTTP POST request to an infection source
Result
Threat name:
Amadey, Discord Token Stealer, LummaC St, EICAR, Lu
Detection:
malicious
Classification:
rans.troj.spyw.expl.evad.mine
Score:
100 / 100
Signature
.NET source code references suspicious native API functions
Adds a directory exclusion to Windows Defender
Allocates memory in foreign processes
Antivirus detection for dropped file
C2 URLs / IPs found in malware configuration
Compiles code for process injection (via .Net compiler)
Connects to a pastebin service (likely for C&C)
Contains functionality to inject code into remote processes
Contains functionality to start a terminal service
Creates a thread in another existing process (thread injection)
Creates multiple autostart registry keys
Detected unpacking (changes PE section rights)
Encrypted powershell cmdline option found
Found direct / indirect Syscall (likely to bypass EDR)
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Found strings related to Crypto-Mining
Hides that the sample has been downloaded from the Internet (zone.identifier)
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Malicious sample detected (through community Yara rule)
Modifies existing user documents (likely ransomware behavior)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Queries memory information (via WMI often done to detect virtual machines)
Queries sensitive physical memory information (via WMI, Win32_PhysicalMemory, often done to detect virtual machines)
Sample uses string decryption to hide its real strings
Sigma detected: Dot net compiler compiles file from suspicious location
Sigma detected: New RUN Key Pointing to Suspicious Folder
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Silenttrinity Stager Msbuild Activity
Suricata IDS alerts for network traffic
Switches to a custom stack to bypass stack traces
Tries to detect process monitoring tools (Task Manager, Process Explorer etc.)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect sandboxes and other dynamic analysis tools (window names)
Tries to evade debugger and weak emulator (self modifying code)
Tries to harvest and steal browser information (history, passwords, etc)
Uses known network protocols on non-standard ports
Uses ping.exe to check the status of other devices and networks
Uses ping.exe to sleep
Uses threadpools to delay analysis
Writes a notice file (html or txt) to demand a ransom
Writes to foreign memory regions
Yara detected Amadey
Yara detected Amadeys Clipper DLL
Yara detected AntiVM3
Yara detected Costura Assembly Loader
Yara detected Discord Token Stealer
Yara detected LummaC Stealer
Yara detected Powershell decode and execute
Yara detected Quasar RAT
Yara detected RHADAMANTHYS Stealer
Yara detected SugarDump
Yara detected Vidar stealer
Yara detected Xmrig cryptocurrency miner
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1704106 Sample: tok.exe Startdate: 02/06/2025 Architecture: WINDOWS Score: 100 134 pastebin.com 2->134 136 plaxyrj.run 2->136 138 15 other IPs or domains 2->138 176 Suricata IDS alerts for network traffic 2->176 178 Found malware configuration 2->178 180 Malicious sample detected (through community Yara rule) 2->180 184 27 other signatures 2->184 12 tok.exe 5 2->12         started        16 Task_Manager.exe 2->16         started        18 ramez.exe 2->18         started        20 Task_Manager.exe 2->20         started        signatures3 182 Connects to a pastebin service (likely for C&C) 134->182 process4 file5 114 C:\Users\user\AppData\Local\...\ramez.exe, PE32 12->114 dropped 116 C:\Users\user\...\ramez.exe:Zone.Identifier, ASCII 12->116 dropped 212 Contains functionality to start a terminal service 12->212 214 Found many strings related to Crypto-Wallets (likely being stolen) 12->214 216 Contains functionality to inject code into remote processes 12->216 22 ramez.exe 1 59 12->22         started        218 Found direct / indirect Syscall (likely to bypass EDR) 16->218 220 Tries to detect process monitoring tools (Task Manager, Process Explorer etc.) 16->220 signatures6 process7 dnsIp8 144 185.156.72.96 ITDELUXE-ASRU Russian Federation 22->144 146 185.156.72.2 ITDELUXE-ASRU Russian Federation 22->146 148 77.83.207.69 DINET-ASRU Russian Federation 22->148 106 C:\Users\user\AppData\...\c5edd8419a.exe, PE32+ 22->106 dropped 108 C:\Users\user\AppData\...\19ee7af34f.exe, PE32 22->108 dropped 110 C:\Users\user\AppData\...\eec980a3e4.exe, PE32 22->110 dropped 112 25 other malicious files 22->112 dropped 200 Multi AV Scanner detection for dropped file 22->200 202 Contains functionality to start a terminal service 22->202 204 Creates multiple autostart registry keys 22->204 27 fipu26A.exe 23 183 22->27         started        32 c0e934008c.exe 22->32         started        34 8f2lGlV.exe 22->34         started        36 4 other processes 22->36 file9 signatures10 process11 dnsIp12 156 ip-api.com 208.95.112.1 TUT-ASUS United States 27->156 158 innocents.ru 104.21.3.181 CLOUDFLARENETUS United States 27->158 166 2 other IPs or domains 27->166 118 C:\Users\user\AppData\Local\Temp\Zip.exe, PE32 27->118 dropped 120 C:\Users\user\AppData\...120ewtonsoft.Json.dll, PE32 27->120 dropped 122 C:\Users\user\AppData\...122HPKIZUUSG.png, ASCII 27->122 dropped 128 5 other malicious files 27->128 dropped 222 Multi AV Scanner detection for dropped file 27->222 224 Queries sensitive physical memory information (via WMI, Win32_PhysicalMemory, often done to detect virtual machines) 27->224 226 Writes a notice file (html or txt) to demand a ransom 27->226 242 3 other signatures 27->242 38 powershell.exe 27->38         started        41 Zip.exe 27->41         started        160 185.208.159.226 SIMPLECARRER2IT Switzerland 32->160 162 raw.githubusercontent.com 185.199.111.133 FASTLYUS Netherlands 32->162 124 C:\Users\user\AppData\...\Task_Manager.exe, PE32+ 32->124 dropped 228 Antivirus detection for dropped file 32->228 230 Detected unpacking (changes PE section rights) 32->230 232 Creates multiple autostart registry keys 32->232 244 3 other signatures 32->244 43 cmd.exe 32->43         started        234 Encrypted powershell cmdline option found 34->234 236 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 34->236 238 Uses threadpools to delay analysis 34->238 45 8f2lGlV.exe 34->45         started        164 chinktickler.anondns.net 196.251.71.231 Web4AfricaZA Seychelles 36->164 168 2 other IPs or domains 36->168 126 C:\Users\user\AppData\Local\Temp\...\csr.exe, PE32+ 36->126 dropped 240 Tries to harvest and steal browser information (history, passwords, etc) 36->240 246 5 other signatures 36->246 48 cmd.exe 36->48         started        50 powershell.exe 36->50         started        52 MSBuild.exe 36->52         started        54 conhost.exe 36->54         started        file13 signatures14 process15 dnsIp16 186 Compiles code for process injection (via .Net compiler) 38->186 188 Loading BitLocker PowerShell Module 38->188 56 conhost.exe 38->56         started        190 Multi AV Scanner detection for dropped file 41->190 192 Uses ping.exe to sleep 43->192 194 Uses ping.exe to check the status of other devices and networks 43->194 58 cmd.exe 43->58         started        61 conhost.exe 43->61         started        170 4.99.4t.com 88.198.124.110 HETZNER-ASDE Germany 45->170 172 t.me 149.154.167.99 TELEGRAMRU United Kingdom 45->172 196 Encrypted powershell cmdline option found 45->196 198 Tries to harvest and steal browser information (history, passwords, etc) 45->198 63 powershell.exe 45->63         started        66 chrome.exe 45->66         started        69 powershell.exe 45->69         started        73 3 other processes 45->73 75 2 other processes 48->75 71 conhost.exe 50->71         started        174 battlefled.top 195.82.147.188 DREAMTORRENT-CORP-ASRU Russian Federation 52->174 signatures17 process18 dnsIp19 77 WmiApSrv.exe 56->77         started        206 Uses ping.exe to sleep 58->206 79 Task_Manager.exe 58->79         started        96 2 other processes 58->96 130 C:\Users\user\AppData\...\sogley2u.cmdline, Unicode 63->130 dropped 208 Writes to foreign memory regions 63->208 210 Creates a thread in another existing process (thread injection) 63->210 82 csc.exe 63->82         started        85 conhost.exe 63->85         started        140 192.168.2.4 unknown unknown 66->140 87 chrome.exe 66->87         started        90 csc.exe 69->90         started        92 conhost.exe 69->92         started        132 C:\Users\user\AppData\Local\...\ruhup301.0.cs, Unicode 73->132 dropped 94 conhost.exe 73->94         started        142 8.8.8.8 GOOGLEUS United States 75->142 file20 signatures21 process22 dnsIp23 248 Antivirus detection for dropped file 79->248 250 Detected unpacking (changes PE section rights) 79->250 252 Tries to detect sandboxes and other dynamic analysis tools (window names) 79->252 254 2 other signatures 79->254 102 C:\Users\user\AppData\Local\...\sogley2u.dll, PE32 82->102 dropped 98 cvtres.exe 82->98         started        150 apis.google.com 87->150 152 plus.l.google.com 142.251.116.100 GOOGLEUS United States 87->152 154 3 other IPs or domains 87->154 104 C:\Users\user\AppData\Local\...\2psomqeu.dll, PE32 90->104 dropped 100 cvtres.exe 90->100         started        file24 signatures25 process26
Threat name:
Win32.Trojan.Amadey
Status:
Malicious
First seen:
2025-05-23 22:59:57 UTC
File Type:
PE (Exe)
Extracted files:
2
AV detection:
20 of 24 (83.33%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
Result
Malware family:
Score:
  10/10
Tags:
family:amadey family:xmrig botnet:8d33eb discovery execution miner persistence spyware stealer
Behaviour
Runs ping.exe
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Browser Information Discovery
Enumerates physical storage devices
System Location Discovery: System Language Discovery
System Network Configuration Discovery: Internet Connection Discovery
Drops file in Windows directory
Adds Run key to start application
Checks installed software on the system
Drops desktop.ini file(s)
Legitimate hosting services abused for malware hosting/C2
Looks up external IP address via web service
Checks BIOS information in registry
Checks computer location settings
Cryptocurrency Miner
Executes dropped EXE
Reads user/profile data of web browsers
Command and Scripting Interpreter: PowerShell
Downloads MZ/PE file
XMRig Miner payload
Xmrig family
xmrig
Malware Config
C2 Extraction:
http://185.156.72.96
Verdict:
Malicious
Tags:
stealc
YARA:
n/a
Unpacked files
SH256 hash:
5ad2cb58c77377f993aaa487843697b5aae8e475591f06503a9c9178e91c568a
MD5 hash:
bceb458a9aa5fa74da8a6a096e9542d3
SHA1 hash:
5cdcabe3fc73263422c8b89b256e3e40cdfdcff7
Detections:
Amadey
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:has_telegram_urls
Author:Aaron DeVera<aaron@backchannel.re>
Description:Detects Telegram URLs
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
Reviews
IDCapabilitiesEvidence
AUTH_APIManipulates User AuthorizationADVAPI32.dll::GetSidSubAuthorityCount
ADVAPI32.dll::GetSidSubAuthority
ADVAPI32.dll::RevertToSelf
COM_BASE_APICan Download & Execute componentsole32.dll::CoCreateInstance
GDI_PLUS_APIInterfaces with Graphicsgdiplus.dll::GdiplusStartup
gdiplus.dll::GdiplusShutdown
gdiplus.dll::GdipGetImageEncodersSize
gdiplus.dll::GdipGetImageEncoders
SECURITY_BASE_APIUses Security Base APIADVAPI32.dll::DuplicateTokenEx
ADVAPI32.dll::GetSidIdentifierAuthority
ADVAPI32.dll::ImpersonateLoggedOnUser
SHELL_APIManipulates System ShellSHELL32.dll::ShellExecuteA
SHELL32.dll::SHFileOperationA
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CreateProcessA
KERNEL32.dll::OpenProcess
ADVAPI32.dll::OpenProcessToken
KERNEL32.dll::VirtualAllocEx
KERNEL32.dll::WriteProcessMemory
KERNEL32.dll::CloseHandle
WININET.dll::InternetCloseHandle
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::LoadLibraryExW
KERNEL32.dll::GetDriveTypeW
KERNEL32.dll::GetSystemInfo
KERNEL32.dll::GetStartupInfoW
KERNEL32.dll::GetCommandLineW
KERNEL32.dll::GetCommandLineA
WIN_BASE_EXEC_APICan Execute other programsKERNEL32.dll::WriteConsoleW
KERNEL32.dll::ReadConsoleW
KERNEL32.dll::SetStdHandle
KERNEL32.dll::GetConsoleMode
KERNEL32.dll::GetConsoleOutputCP
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CreateDirectoryA
KERNEL32.dll::CreateFileA
KERNEL32.dll::CreateFileW
KERNEL32.dll::DeleteFileW
KERNEL32.dll::GetFileAttributesA
KERNEL32.dll::RemoveDirectoryA
WIN_BASE_USER_APIRetrieves Account InformationADVAPI32.dll::GetUserNameA
ADVAPI32.dll::LookupAccountNameA
WIN_REG_APICan Manipulate Windows RegistryADVAPI32.dll::RegGetValueA
ADVAPI32.dll::RegOpenKeyExA
ADVAPI32.dll::RegQueryInfoKeyW
ADVAPI32.dll::RegQueryValueExA
ADVAPI32.dll::RegSetValueExA
WIN_SOCK_APIUses Network to send and receive dataWS2_32.dll::freeaddrinfo
WS2_32.dll::getaddrinfo

Comments