🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7f458de2c296e05095974afdb4203994899017df91d66a99c86c982123e09bc2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Amadey


Vendor detections: 4


Intelligence 4 IOCs YARA 20 File information Comments

SHA256 hash: 7f458de2c296e05095974afdb4203994899017df91d66a99c86c982123e09bc2
SHA3-384 hash: a05337b912f6de3a310a218a75923a6e548bbf214bdb42337b3fc496cdf61e9074a3982aa515e638e8ce54dcd474001f
SHA1 hash: 66bd0a6092faadc3ae1e2fba407a846970de4ba9
MD5 hash: 6c7cb089417e3083944f238dac2f0c2b
humanhash: pluto-mirror-ink-may
File name:systemenv.bin
Download: download sample
Signature Amadey
File size:23'629'027 bytes
First seen:2025-05-28 14:20:24 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 393216:x0o3aYCcwc5zADUpK/hKDjzbWzDiG1CPwDvt3uFVCzSq/dVlStgrz005Ll:/XCcwqnK/hKfzbmDpz00Jl
TLSH T170379D13B6A78CE2F9F70230DAF453675526BD050B3280DB92841F3BAD332D19A79766
TrID 48.8% (.SH3D) Sweet Home 3D Design (generic) (10500/1/3)
32.5% (.MAFF) Mozilla Archive Format (gen) (7000/1/1)
18.6% (.ZIP) ZIP compressed archive (4000/1)
Magika zip
Reporter aachum
Tags:96e744 Amadey dropped-by-ACRStealer HIjackLoader IDATLoader zip


Avatar
iamaachum
https://mi.citationcompany.bet/systemenv.bin

Amadey Botnet: 96E744
Amadey C2: http://mi.ultimateamplifier.world/dash/png/index.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
88
Origin country :
ES ES
File Archive Information

This file archive contains 16 file(s), sorted by their relevance:

File name:MSVCP140.dll
File size:447'568 bytes
SHA256 hash: 654412a50c83d218d9f72f8bbd0e0d2963ed0b58be59d6661e931f32dc9f80d8
MD5 hash: 05f1b8a11885aa248408597f25ee9d47
MIME type:application/x-dosexec
Signature Amadey
File name:sqlite3_plex.dll
File size:662'512 bytes
SHA256 hash: 31c9cfe9835a138d06abe5e70f7bd99ab25e308a21e43b526bc808a2156065cf
MD5 hash: 45b0abc0be9d9f66cc060721b834c38a
MIME type:application/x-dosexec
Signature Amadey
File name:icudt69.dll
File size:11'057'136 bytes
SHA256 hash: 45c40f392da7893aa92ad200ba63560c1b862b87aae8c32bc3f545dbdb58e4cf
MD5 hash: 962afef42974c27d13e28c8bd1172991
MIME type:application/x-dosexec
Signature Amadey
File name:boost_locale.dll
File size:378'112 bytes
SHA256 hash: 1ce12d4c0c3fd8d3c8912fd94ebdf54ff5ff5825c5f3813ce1b3ec6e46d8fd52
MD5 hash: 9ba6713af2927e4b60a9352f8c85fe7d
MIME type:application/x-dosexec
Signature Amadey
File name:icuuc69.dll
File size:1'827'584 bytes
SHA256 hash: c4b335f491a0822d31d43254cfe42c109c5f84bd3f8530beda560cda3e546d77
MD5 hash: c3b8ac214c04886923d3fcce79438b72
MIME type:application/x-dosexec
Signature Amadey
File name:fmt.dll
File size:115'968 bytes
SHA256 hash: 6c17efa9e1d9cc444d1e2dd72aed7c111f0eea454c34728802a20f167fd6ccad
MD5 hash: 00078f525f333efff7300ef3edb5a2d9
MIME type:application/x-dosexec
Signature Amadey
File name:nghttp2.dll
File size:121'104 bytes
SHA256 hash: 793214f2192ff91ce23db55decd0d121126ca4a212cc3cc1b20ccc4381b21d61
MD5 hash: 38cae048eebab137a7005abcd146558a
MIME type:application/x-dosexec
Signature Amadey
File name:VCRUNTIME140.dll
File size:91'216 bytes
SHA256 hash: 63f98f7eb2b42d4e416d1a0e5631becb5ee6ee09393913b4e0d9b4b852355172
MD5 hash: fd82c7b4ee2c40adaae774d7357426d3
MIME type:application/x-dosexec
Signature Amadey
File name:Sungwaibflot.odl
File size:1'615'286 bytes
SHA256 hash: 054524a687088c03b8ae4dca72fb517a3dd906ee6424f9057ed1e829ed58b34d
MD5 hash: a451ccb7c5067d9d4a0ac76135cb794a
MIME type:application/octet-stream
Signature Amadey
File name:libssl-3.dll
File size:440'816 bytes
SHA256 hash: 515d25304515345d67ed45e7fed14b7f547dba013302f8de64fee9e2dc237943
MD5 hash: 705eaf66960e39db680e8582a1f9cccd
MIME type:application/x-dosexec
Signature Amadey
File name:icuin69.dll
File size:2'791'120 bytes
SHA256 hash: 1bad2711c965cd964c2f2a588a53663e63f1a23fa0e72a9519ac36e542b0c16d
MD5 hash: 116db547209b25eaf4ef2388abb50ee6
MIME type:application/x-dosexec
Signature Amadey
File name:boost_filesystem.dll
File size:118'480 bytes
SHA256 hash: ff22a5d2497a2719881cba3ecf02f59813fe525fb19233fb12a5228227e34944
MD5 hash: 0fd14a7ea07f89a705fa1ec3e9ef2cc1
MIME type:application/x-dosexec
Signature Amadey
File name:libcrypto-3.dll
File size:2'668'752 bytes
SHA256 hash: 3335b1466292fd6d6e13d554e01199461941214f6565fbae82ce54730f49b28c
MD5 hash: 3a0c7e8f0411818f1b6ac3c2365195a3
MIME type:application/x-dosexec
Signature Amadey
File name:oneauth.exe
File size:846'608 bytes
SHA256 hash: 44ba08b293958df880adf1e932aa8afcdc6cd0598f600475ac6ac9fe0299ab34
MD5 hash: ab59ce9a4806633697e02cd7df17e3a0
MIME type:application/x-dosexec
Signature Amadey
File name:Chand.pw
File size:74'623 bytes
SHA256 hash: 7de9847efa7dd1c7899b91408952bd1002c959065bab3b5dc54c5385c1735e92
MD5 hash: 7a10e93b302a781989d6635b761c1716
MIME type:application/octet-stream
Signature Amadey
File name:libcurl.dll
File size:369'920 bytes
SHA256 hash: 29b5d49e53f4a8cadb2085c1e5c18fa16eb1a1e02d7bf3209378109201a6fb67
MD5 hash: fa24b81b2a5fa73db503bbfe91f7a854
MIME type:application/x-dosexec
Signature Amadey
Vendor Threat Intelligence
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
microsoft_visual_cc signed
Gathering data
Result
Malware family:
Score:
  10/10
Tags:
family:amadey botnet:96e744 discovery execution trojan
Behaviour
Suspicious use of WriteProcessMemory
Program crash
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:adonunix2
Author:Tim Brown @timb_machine
Description:AD on UNIX
Rule name:BitcoinAddress
Author:Didier Stevens (@DidierStevens)
Description:Contains a valid Bitcoin address
Rule name:BLOWFISH_Constants
Author:phoul (@phoul)
Description:Look for Blowfish constants
Rule name:Check_OutputDebugStringA_iat
Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:ldpreload
Author:xorseed
Reference:https://stuff.rop.io/
Rule name:maldoc_getEIP_method_1
Author:Didier Stevens (https://DidierStevens.com)
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:meth_get_eip
Author:Willi Ballenthin
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
Rule name:test_Malaysia
Author:rectifyq
Description:Detects file containing malaysia string
Rule name:WHIRLPOOL_Constants
Author:phoul (@phoul)
Description:Look for WhirlPool constants

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Amadey

zip 7f458de2c296e05095974afdb4203994899017df91d66a99c86c982123e09bc2

(this sample)

  
Dropped by
ACRStealer
  
Delivery method
Distributed via web download

Comments