Threat name:
Amadey, AsyncRAT, Healer AV Disabler, Lu
Alert
Classification:
phis.troj.spyw.evad
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
Allocates memory in foreign processes
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Antivirus detection for URL or domain
Binary is likely a compiled AutoIt script file
C2 URLs / IPs found in malware configuration
Creates multiple autostart registry keys
Detected unpacking (changes PE section rights)
Disable Windows Defender notifications (registry)
Disable Windows Defender real time protection (registry)
Disables Windows Defender Tamper protection
Drops PE files with a suspicious file extension
Found API chain indicative of sandbox detection
Found malware configuration
Hides threads from debuggers
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Machine Learning detection for dropped file
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Modifies windows update settings
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file contains section with special chars
Sample uses string decryption to hide its real strings
Sigma detected: Invoke-Obfuscation CLIP+ Launcher
Sigma detected: Invoke-Obfuscation VAR+ Launcher
Sigma detected: New RUN Key Pointing to Suspicious Folder
Sigma detected: Powershell download and execute file
Sigma detected: PowerShell DownloadFile
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Search for Antivirus process
Sigma detected: Suspicious Command Patterns In Scheduled Task Creation
Sigma detected: Suspicious MSHTA Child Process
Sigma detected: Suspicious Script Execution From Temp Folder
Sigma detected: WScript or CScript Dropper
Suricata IDS alerts for network traffic
Suspicious powershell command line found
Tries to detect process monitoring tools (Task Manager, Process Explorer etc.)
Tries to detect sandboxes / dynamic malware analysis system (registry check)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect sandboxes and other dynamic analysis tools (window names)
Tries to detect virtualization through RDTSC time measurements
Tries to download and execute files (via powershell)
Tries to evade debugger and weak emulator (self modifying code)
Uses schtasks.exe or at.exe to add and modify task schedules
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
Wscript called in batch mode (surpress errors)
Yara detected Amadeys stealer DLL
Yara detected Costura Assembly Loader
Yara detected Healer AV Disabler
Yara detected LummaC Stealer
Yara detected obfuscated html page
Yara detected Powershell download and execute
Yara detected PureLog Stealer
behaviorgraph
top1
dnsIp2
2
Behavior Graph
ID:
1612327
Sample:
DhqvS8pXj8.exe
Startdate:
11/02/2025
Architecture:
WINDOWS
Score:
100
139
toppyneedus.biz
2->139
141
suggestyuoz.biz
2->141
143
8 other IPs or domains
2->143
159
Suricata IDS alerts
for network traffic
2->159
161
Found malware configuration
2->161
163
Malicious sample detected
(through community Yara
rule)
2->163
165
37 other signatures
2->165
11
skotes.exe
2
57
2->11
started
16
DhqvS8pXj8.exe
5
2->16
started
18
afccf6841f.exe
2->18
started
20
7 other processes
2->20
signatures3
process4
dnsIp5
145
185.215.113.16, 49742, 49754, 49766
WHOLESALECONNECTIONSNL
Portugal
11->145
147
185.215.113.43, 49737, 49738, 49741
WHOLESALECONNECTIONSNL
Portugal
11->147
149
185.215.113.75, 49739, 49790, 49819
WHOLESALECONNECTIONSNL
Portugal
11->149
111
C:\Users\user\AppData\Local\...\Fe36XBk.exe, PE32
11->111
dropped
113
C:\Users\user\AppData\Local\...\7fOMOTQ.exe, PE32
11->113
dropped
115
C:\Users\user\AppData\Local\...\L5shRfh.exe, PE32
11->115
dropped
123
20 other malicious files
11->123
dropped
211
Creates multiple autostart
registry keys
11->211
213
Hides threads from debuggers
11->213
215
Tries to detect sandboxes
/ dynamic malware analysis
system (registry check)
11->215
217
Tries to detect process
monitoring tools (Task
Manager, Process Explorer
etc.)
11->217
22
afccf6841f.exe
1
11->22
started
26
cmd.exe
11->26
started
28
dc785309cb.exe
11->28
started
38
3 other processes
11->38
117
C:\Users\user\AppData\Local\...\skotes.exe, PE32
16->117
dropped
119
C:\Users\user\...\skotes.exe:Zone.Identifier, ASCII
16->119
dropped
219
Detected unpacking (changes
PE section rights)
16->219
221
Tries to evade debugger
and weak emulator (self
modifying code)
16->221
223
Tries to detect virtualization
through RDTSC time measurements
16->223
30
skotes.exe
16->30
started
121
C:\Users\user\AppData\Local\...\wucgjnAiS.hta, HTML
18->121
dropped
225
Binary is likely a compiled
AutoIt script file
18->225
227
Creates HTA files
18->227
32
mshta.exe
18->32
started
34
cmd.exe
18->34
started
229
Multi AV Scanner detection
for dropped file
20->229
231
Suspicious powershell
command line found
20->231
233
Machine Learning detection
for dropped file
20->233
235
2 other signatures
20->235
36
cmd.exe
20->36
started
40
4 other processes
20->40
file6
signatures7
process8
file9
105
C:\Users\user\AppData\Local\...\2C3I1mD9d.hta, HTML
22->105
dropped
175
Binary is likely a compiled
AutoIt script file
22->175
177
Machine Learning detection
for dropped file
22->177
179
Found API chain indicative
of sandbox detection
22->179
42
mshta.exe
1
22->42
started
45
cmd.exe
1
22->45
started
52
2 other processes
26->52
47
cmd.exe
28->47
started
181
Multi AV Scanner detection
for dropped file
30->181
183
Detected unpacking (changes
PE section rights)
30->183
199
5 other signatures
30->199
185
Suspicious powershell
command line found
32->185
187
Tries to download and
execute files (via powershell)
32->187
50
powershell.exe
32->50
started
54
2 other processes
34->54
107
C:\Temp\i2GY6vn5L.hta, HTML
36->107
dropped
189
Creates HTA files
36->189
56
2 other processes
36->56
191
Tries to detect sandboxes
and other dynamic analysis
tools (process name
or module or function)
38->191
193
Writes to foreign memory
regions
38->193
195
Allocates memory in
foreign processes
38->195
197
Injects a PE file into
a foreign processes
38->197
58
3 other processes
38->58
60
3 other processes
40->60
signatures10
process11
file12
201
Suspicious powershell
command line found
42->201
203
Tries to download and
execute files (via powershell)
42->203
62
powershell.exe
15
18
42->62
started
205
Drops PE files with
a suspicious file extension
45->205
207
Uses schtasks.exe or
at.exe to add and modify
task schedules
45->207
76
2 other processes
45->76
131
C:\Users\user\AppData\...\Macromedia.com, PE32
47->131
dropped
66
Macromedia.com
47->66
started
78
11 other processes
47->78
133
TempOBIIERT8JWKOKQBWJVVZGBZ2TJW54YEP.EXE, PE32
50->133
dropped
68
TempOBIIERT8JWKOKQBWJVVZGBZ2TJW54YEP.EXE
50->68
started
70
conhost.exe
50->70
started
135
C:\Temp\v468GkyBl.hta, HTML
52->135
dropped
209
Creates HTA files
52->209
72
mshta.exe
52->72
started
80
6 other processes
52->80
74
powershell.exe
56->74
started
137
C:\ProgramData\jhbbvnx\fbpbh.exe, PE32
58->137
dropped
signatures13
process14
file15
125
TempMHLZAGA5NZFMG2ZDILNZW0CTFV5YR4HM.EXE, PE32
62->125
dropped
237
Powershell drops PE
file
62->237
82
TempMHLZAGA5NZFMG2ZDILNZW0CTFV5YR4HM.EXE
62->82
started
85
conhost.exe
62->85
started
127
C:\Users\user\AppData\...\AchillesGuard.com, PE32
66->127
dropped
129
C:\Users\user\AppData\...\AchillesGuard.js, ASCII
66->129
dropped
239
Drops PE files with
a suspicious file extension
66->239
87
schtasks.exe
66->87
started
241
Detected unpacking (changes
PE section rights)
68->241
243
Tries to detect sandboxes
and other dynamic analysis
tools (window names)
68->243
245
Machine Learning detection
for dropped file
68->245
251
4 other signatures
68->251
247
Suspicious powershell
command line found
72->247
249
Tries to download and
execute files (via powershell)
72->249
89
powershell.exe
72->89
started
92
powershell.exe
80->92
started
94
powershell.exe
80->94
started
96
powershell.exe
80->96
started
signatures16
process17
file18
151
Detected unpacking (changes
PE section rights)
82->151
153
Machine Learning detection
for dropped file
82->153
155
Modifies windows update
settings
82->155
157
7 other signatures
82->157
98
conhost.exe
87->98
started
109
C:\Users\...\483d2fa8a0d53818306efeb32d3.exe, PE32
89->109
dropped
100
483d2fa8a0d53818306efeb32d3.exe
89->100
started
103
conhost.exe
89->103
started
signatures19
process20
signatures21
167
Detected unpacking (changes
PE section rights)
100->167
169
Tries to evade debugger
and weak emulator (self
modifying code)
100->169
171
Hides threads from debuggers
100->171
173
2 other signatures
100->173
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.