🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 84f5a7a0105a792cf1d8d2cf4257b7fafdeb77dc3bf320d7880097e4f4d6dfa1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Amadey


Vendor detections: 18


Intelligence 18 IOCs YARA 17 File information Comments

SHA256 hash: 84f5a7a0105a792cf1d8d2cf4257b7fafdeb77dc3bf320d7880097e4f4d6dfa1
SHA3-384 hash: c336c4041a23e3afb20ad557bb0ed7c4c17010427ae3d202cbe762cad1c3e1cd472e5683e385ffc66f41bcb06a78c738
SHA1 hash: e88a926c9e5930637a3b5bb121408a7e7ba30a24
MD5 hash: f564e3ac1adea29cf04e1dc14717d62e
humanhash: jersey-juliet-mango-oregon
File name:exe (2)
Download: download sample
Signature Amadey
File size:5'833'049 bytes
First seen:2025-04-15 11:32:18 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 646167cce332c1c252cdcb1839e0cf48 (8'474 x RedLineStealer, 4'855 x Amadey, 290 x Smoke Loader)
ssdeep 98304:Tjg/RdNSPIMaOrhOWpvJ8q1QDtAIeDFO+pQ2VxLt8EfDqTDLRApxwjXEQPZT:XiDNQI/gh9J8q1KtAIaPuy5t8E8LapxK
TLSH T1FE463357BBE00835CCA8527004F603921A74BEE657227257635F6FAB0CE39E5877632B
TrID 37.8% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
20.0% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
12.7% (.EXE) Win64 Executable (generic) (10522/11/4)
7.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
Magika pebin
dhash icon f8f0f4c8c8c8d8f0 (8'804 x RedLineStealer, 5'109 x Amadey, 288 x Smoke Loader)
Reporter JAMESWT_WT
Tags:185-250-151-155 Amadey exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
443
Origin country :
IT IT
Vendor Threat Intelligence
Malware family:
ID:
1
File name:
exe2.exe
Verdict:
Malicious activity
Analysis date:
2025-04-15 11:36:24 UTC
Tags:
lumma stealer amadey stealc botnet rdp themida

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.1%
Tags:
phishing autorun
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Creating a file in the %temp% subdirectories
Creating a process from a recently created file
Creating a process with a hidden window
Сreating synchronization primitives
Searching for analyzing tools
Creating a file
Creating a window
Searching for synchronization primitives
Behavior that indicates a threat
DNS request
Connection attempt
Sending a custom TCP request
Connection attempt to an infection source
Query of malicious DNS domain
Enabling autorun by creating a file
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context anti-vm anti-vm CAB crypt cryptbot explorer installer installer lolbin microsoft_visual_cc overlay packed packed packer_detected rundll32 runonce sfx
Result
Threat name:
Amadey, LummaC Stealer
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Contains functionality to start a terminal service
Detected unpacking (changes PE section rights)
Found malware configuration
Hides threads from debuggers
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file contains section with special chars
Potentially malicious time measurement code found
Sample uses string decryption to hide its real strings
Suricata IDS alerts for network traffic
Tries to detect process monitoring tools (Task Manager, Process Explorer etc.)
Tries to detect sandboxes / dynamic malware analysis system (registry check)
Tries to detect sandboxes and other dynamic analysis tools (window names)
Tries to detect virtualization through RDTSC time measurements
Tries to evade debugger and weak emulator (self modifying code)
Yara detected Amadey
Yara detected Amadeys Clipper DLL
Yara detected LummaC Stealer
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1665317 Sample: exe (2).exe Startdate: 15/04/2025 Architecture: WINDOWS Score: 100 44 wxayfarer.live 2->44 46 triplooqp.world 2->46 48 8 other IPs or domains 2->48 54 Suricata IDS alerts for network traffic 2->54 56 Found malware configuration 2->56 58 Antivirus detection for URL or domain 2->58 60 11 other signatures 2->60 9 exe (2).exe 1 4 2->9         started        12 rapes.exe 2->12         started        15 rapes.exe 12 2->15         started        18 2 other processes 2->18 signatures3 process4 dnsIp5 40 C:\Users\user\AppData\Local\...\y7c02.exe, PE32 9->40 dropped 42 C:\Users\user\AppData\Local\...\3n24Z.exe, PE32 9->42 dropped 20 y7c02.exe 1 4 9->20         started        80 Antivirus detection for dropped file 12->80 82 Multi AV Scanner detection for dropped file 12->82 84 Detected unpacking (changes PE section rights) 12->84 92 5 other signatures 12->92 52 176.113.115.6, 80 SELECTELRU Russian Federation 15->52 86 Contains functionality to start a terminal service 15->86 88 Hides threads from debuggers 15->88 90 Tries to detect sandboxes / dynamic malware analysis system (registry check) 15->90 file6 signatures7 process8 file9 34 C:\Users\user\AppData\Local\...\2U7495.exe, PE32 20->34 dropped 36 C:\Users\user\AppData\Local\...\1l74Y4.exe, PE32 20->36 dropped 62 Antivirus detection for dropped file 20->62 64 Multi AV Scanner detection for dropped file 20->64 24 1l74Y4.exe 4 20->24         started        28 2U7495.exe 20->28         started        signatures10 process11 dnsIp12 38 C:\Users\user\AppData\Local\...\rapes.exe, PE32 24->38 dropped 66 Antivirus detection for dropped file 24->66 68 Multi AV Scanner detection for dropped file 24->68 70 Detected unpacking (changes PE section rights) 24->70 78 3 other signatures 24->78 31 rapes.exe 24->31         started        50 steamcommunity.com 184.30.122.179, 443, 49684, 49685 AKAMAI-ASUS United States 28->50 72 Tries to evade debugger and weak emulator (self modifying code) 28->72 74 Hides threads from debuggers 28->74 76 Tries to detect sandboxes / dynamic malware analysis system (registry check) 28->76 file13 signatures14 process15 signatures16 94 Contains functionality to start a terminal service 31->94 96 Hides threads from debuggers 31->96 98 Tries to detect sandboxes / dynamic malware analysis system (registry check) 31->98 100 Tries to detect process monitoring tools (Task Manager, Process Explorer etc.) 31->100
Threat name:
Win32.Trojan.LummaStealer
Status:
Malicious
First seen:
2025-03-22 21:18:10 UTC
File Type:
PE (Exe)
Extracted files:
79
AV detection:
21 of 24 (87.50%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
lummastealer
Similar samples:
Result
Malware family:
Score:
  10/10
Tags:
family:amadey family:lumma botnet:092155 defense_evasion discovery persistence stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Drops file in Windows directory
Suspicious use of NtSetInformationThreadHideFromDebugger
Adds Run key to start application
Checks BIOS information in registry
Checks computer location settings
Executes dropped EXE
Identifies Wine through registry keys
Identifies VirtualBox via ACPI registry values (likely anti-VM)
Amadey
Amadey family
Lumma Stealer, LummaC
Lumma family
Malware Config
C2 Extraction:
http://176.113.115.6
https://wxayfarer.live/ALosnz
https://r1qesccapewz.run/ANSbwqy
https://1travewlio.shop/ZNxbHi
https://touvrlane.bet/ASKwjq
https://fsighbtseeing.shop/ASJnzh
https://advennture.top/GKsiio
https://targett.top/dsANGt
https://holidamyup.today/AOzkns
https://triplooqp.world/APowko
Verdict:
Malicious
Tags:
stealer redline Win.Downloader.Amadey-9986882-0
YARA:
detect_Redline_Stealer
Unpacked files
SH256 hash:
84f5a7a0105a792cf1d8d2cf4257b7fafdeb77dc3bf320d7880097e4f4d6dfa1
MD5 hash:
f564e3ac1adea29cf04e1dc14717d62e
SHA1 hash:
e88a926c9e5930637a3b5bb121408a7e7ba30a24
SH256 hash:
dcd5c3c11e6128f88dee41dd0cb9d23913d4b4a8fc4ebf394a019a16d66fd870
MD5 hash:
f4a3a3defca306376d5d9b1bd48e2f3c
SHA1 hash:
e3c6cb945a397a819ee20f79a7672a9943a78282
SH256 hash:
b705d680fd4759e2212b603389125d73d05f08a6bde82672e96a33ba3a8b7951
MD5 hash:
9a9887854c4a40ef2d59fa077cc70592
SHA1 hash:
2c66df86c12255e4c73a85e235d9ee2d0ba67171
Detections:
win_redline_wextract_hunting_oct_2023
SH256 hash:
1223915d286f489a9dc2b44546ec0562d8e9b923d83229586d350a1b9529de84
MD5 hash:
5719e44c1000196e04a34a2916832b93
SHA1 hash:
e849fe8bd038dfa108d40e421171e01f456b2abd
Detections:
Amadey
SH256 hash:
ccdbd76af5e26b67006d2e35aebd2724c153d9361e4d7aacb145e06e9bfbedea
MD5 hash:
725c91baf8a41704ba0bf98ef73fcaf3
SHA1 hash:
a4ac1c7bc12df3744d8d083c7a35fbb2fc1c4bda
Detections:
Amadey
SH256 hash:
2e85d1bbf3d056d2f37afc162c31ebc4cd13e5b8a95fb228c19452677ecda273
MD5 hash:
ceb93acc0cfa344a28938b6bfbd40808
SHA1 hash:
fedf263152c1269ba6bbdae6e336d10d6ebdbaa1
SH256 hash:
4de1188996477c60a7990ac6d30fb9308727b17197099b66701ae2d110fe4054
MD5 hash:
7fe6b3530d8309c5a80f6355036019a3
SHA1 hash:
88301dc548b9c880d83e000150303d95ab54c94e
Detections:
stealc
SH256 hash:
3a2c63244ba13d224df639ca3bf90ac0d22f4fb8c04ad4b9df1c10938129b262
MD5 hash:
c82dd58f6d8a0989b372ced53ca1815e
SHA1 hash:
256f427d8812a78de928769e64fc718118550f8b
Detections:
win_redline_wextract_hunting_oct_2023
SH256 hash:
4d1558f4bbc2dd2f283d4a21250c7521325b126c36558a51a543ddf32ca213d8
MD5 hash:
fcd8c6c5c238ccb21005c94d3152b0d8
SHA1 hash:
fb9f00187eac32fd9cc538e8eec29acf054257b0
SH256 hash:
76bc449c97692c6e6861c8182cbffb1e68ac510a3405d5d7f1a7a1479ca1598f
MD5 hash:
1644ecf9fed4c438d0f65f2b54da0bd8
SHA1 hash:
4a2feeee65b8203cda5a4c4224d0e88959745ac7
SH256 hash:
c2d72db04670f63488a7d087742c4f68d9be5a45d2be6bfe6dcd721898227ea7
MD5 hash:
c8d031abb4b269655769a7bdc94147b4
SHA1 hash:
c6df630066f6f01502d79b284cf50f1a6214b617
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:command_and_control
Author:CD_R0M_
Description:This rule searches for common strings found by malware using C2. Based on a sample used by a Ransomware group
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:Detect_PowerShell_Obfuscation
Author:daniyyell
Description:Detects obfuscated PowerShell commands commonly used in malicious scripts.
Rule name:detect_Redline_Stealer
Author:Varp0s
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:infostealer_win_stealc_standalone
Description:Find standalone Stealc sample based on decryption routine or characteristic strings
Reference:https://blog.sekoia.io/stealc-a-copycat-of-vidar-and-raccoon-infostealers-gaining-in-popularity-part-1/
Rule name:malware_Stealc_str
Author:JPCERT/CC Incident Response Group
Description:Stealc infostealer
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:pe_detect_tls_callbacks
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:Stealc
Author:kevoreilly
Description:Stealc Payload
Rule name:Stealer_Stealc
Author:Still
Description:attempts to match instructions/strings found in Stealc
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques
Rule name:Windows_Generic_Threat_2bba6bae
Author:Elastic Security
Rule name:win_stealc_generic
Author:dubfib
Rule name:win_stealc_w0
Author:crep1x
Description:Find standalone Stealc sample based on decryption routine or characteristic strings
Reference:https://blog.sekoia.io/stealc-a-copycat-of-vidar-and-raccoon-infostealers-gaining-in-popularity-part-1/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
Reviews
IDCapabilitiesEvidence
AUTH_APIManipulates User AuthorizationADVAPI32.dll::AllocateAndInitializeSid
ADVAPI32.dll::EqualSid
ADVAPI32.dll::FreeSid
SECURITY_BASE_APIUses Security Base APIADVAPI32.dll::AdjustTokenPrivileges
ADVAPI32.dll::GetTokenInformation
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CreateProcessA
ADVAPI32.dll::OpenProcessToken
KERNEL32.dll::CloseHandle
KERNEL32.dll::CreateThread
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::LoadLibraryA
KERNEL32.dll::LoadLibraryExA
KERNEL32.dll::GetDriveTypeA
KERNEL32.dll::GetVolumeInformationA
KERNEL32.dll::GetSystemInfo
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CreateDirectoryA
KERNEL32.dll::CreateFileA
KERNEL32.dll::DeleteFileA
KERNEL32.dll::GetWindowsDirectoryA
KERNEL32.dll::GetSystemDirectoryA
KERNEL32.dll::GetFileAttributesA
WIN_BASE_USER_APIRetrieves Account InformationADVAPI32.dll::LookupPrivilegeValueA
WIN_REG_APICan Manipulate Windows RegistryADVAPI32.dll::RegCreateKeyExA
ADVAPI32.dll::RegOpenKeyExA
ADVAPI32.dll::RegQueryInfoKeyA
ADVAPI32.dll::RegQueryValueExA
ADVAPI32.dll::RegSetValueExA
WIN_USER_APIPerforms GUI ActionsUSER32.dll::PeekMessageA

Comments