MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 aa3ec6bd662f64b5471ba79945d9e620adb66cae5e2887e44eea03d8abc99c73. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Amadey


Vendor detections: 13


Intelligence 13 IOCs YARA 1 File information Comments

SHA256 hash: aa3ec6bd662f64b5471ba79945d9e620adb66cae5e2887e44eea03d8abc99c73
SHA3-384 hash: 3111b4e9d6d4e128b90858c68f8d6f238df9f628849fa05a5f345a01de83350f7b0a3fd8aa80aadd87dcdc21fda2843c
SHA1 hash: e1c1a8a9d67b3dc8cdce7f357dedf81cfe360ec1
MD5 hash: 7b0e7c8cc9ca514381a6bfecf879b650
humanhash: lemon-east-social-west
File name:file
Download: download sample
Signature Amadey
File size:1'170'944 bytes
First seen:2026-08-01 05:02:29 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
ssdeep 6144:g8iG8Xp2Ee6pk2q1h4ZGDecJt/XYjitMaazLx6qtstbBDT4SVBcnnILHlTc1rBXZ:cg1nD6jaakTc9VEAFC02SpDsaMOdVz
TLSH T130450B8ED59257B4B382FB63521EDA225DF6324680729A31CF453E364F02F34A129EDD
TrID 51.9% (.EXE) Win64 Executable (generic) (6522/11/2)
16.1% (.EXE) OS/2 Executable (generic) (2029/13)
15.9% (.EXE) Generic Win/DOS Executable (2002/3)
15.9% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
Reporter abuse_ch
Tags:Amadey exe upx-dec


Avatar
abuse_ch
UPX decompressed file, sourced from SHA256 3fed685e1b41d37f28a2fbd69ee3755ab4797b5d9b60ca6d904b2c9529af12f8
File size (compressed) :325'632 bytes
File size (de-compressed) :1'170'944 bytes
Format:win64/pe
Packed file: 3fed685e1b41d37f28a2fbd69ee3755ab4797b5d9b60ca6d904b2c9529af12f8

Intelligence


File Origin
# of uploads :
1
# of downloads :
298
Origin country :
NL NL
Vendor Threat Intelligence
No detections
Malware family:
ID:
1
File name:
aa3ec6bd662f64b5471ba79945d9e620adb66cae5e2887e44eea03d8abc99c73.zip
Verdict:
Malicious activity
Analysis date:
2026-08-01 05:38:03 UTC
Tags:
arch-exec vidar stealer telegram stealc opendir loader amadey botnet gcleaner nemucod auto generic credentialflusher attachments attc-unc evasion winring0-sys vuln-driver miner xmrig upx sainbox rat tofsee delphi inno installer ip-check njrat xworm golang bladabindi

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Сreating synchronization primitives
DNS request
Connection attempt
Behavior that indicates a threat
Sending a custom TCP request
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
adaptive-context microsoft_visual_cc packed vidar
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-08-01T03:20:00Z UTC
Last seen:
2026-08-03T03:33:00Z UTC
Hits:
~1000
Gathering data
Result
Threat name:
Amadey, Vidar, Xmrig
Detection:
malicious
Classification:
troj.adwa.spyw.evad.mine
Score:
100 / 100
Signature
Adds a directory exclusion to Windows Defender
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Connects to a pastebin service (likely for C&C)
Creates an undocumented autostart registry key
Creates multiple autostart registry keys
Drops PE files to the startup folder
Drops PE files to the user root directory
Found direct / indirect Syscall (likely to bypass EDR)
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Hides that the sample has been downloaded from the Internet (zone.identifier)
Hides threads from debuggers
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Maps a DLL or memory area into another process
Modifies the context of a thread in another process (thread injection)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Queries Google from non browser process on port 80
Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes)
Sample uses string decryption to hide its real strings
Self deletion via cmd or bat file
Sigma detected: New RUN Key Pointing to Suspicious Folder
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Suspicious Environment Variable Has Been Registered
Suricata IDS alerts for network traffic
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect virtualization through RDTSC time measurements
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Unusual module load detection (module proxying)
Uses schtasks.exe or at.exe to add and modify task schedules
Yara detected Amadey
Yara detected Amadeys Clipper DLL
Yara detected Vidar stealer
Yara detected Xmrig cryptocurrency miner
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1950903 Sample: file.exe Startdate: 01/08/2026 Architecture: WINDOWS Score: 100 146 pastebin.com 2->146 148 vog.cau777.org 2->148 150 46 other IPs or domains 2->150 204 Suricata IDS alerts for network traffic 2->204 206 Found malware configuration 2->206 208 Antivirus detection for URL or domain 2->208 212 13 other signatures 2->212 11 windowsruntime.exe 3 65 2->11         started        16 file.exe 1 4 2->16         started        18 ccf8547a57.exe 2->18         started        20 7 other processes 2->20 signatures3 210 Connects to a pastebin service (likely for C&C) 146->210 process4 dnsIp5 174 130.12.182.175, 49791, 8080 VPSDEDICATED-ASUS Slovenia 11->174 176 196.251.107.248, 49782, 49783, 49785 FEMOITGB Germany 11->176 178 62.60.226.185, 49786, 80 FEMOITGB Germany 11->178 110 C:\Users\user\AppData\Local\...\4BtqZz1.exe, PE32+ 11->110 dropped 112 C:\Users\user\AppData\Local\...\s0907.exe, PE32+ 11->112 dropped 114 C:\Users\user\AppData\Local\Temp\...\21.exe, PE32 11->114 dropped 120 11 other malicious files 11->120 dropped 238 Multi AV Scanner detection for dropped file 11->238 240 Creates multiple autostart registry keys 11->240 22 file.exe 11->22         started        26 s0907.exe 19 11->26         started        29 4BtqZz1.exe 13 11->29         started        39 2 other processes 11->39 180 62.60.226.140, 49781, 49784, 80 FEMOITGB Germany 16->180 182 vog.cau777.org 104.21.30.254, 443, 49770, 49774 CLOUDFLARENET-CloudflareIncUS Canada 16->182 184 t.me 149.154.167.99, 443, 49769, 49788 TELEGRAMVG United Kingdom 16->184 116 C:\Users\user\AppData\Local\...\bd1b32ab.exe, PE32 16->116 dropped 118 C:\Users\user\AppData\Local\...\8d880b0a.dll, PE32+ 16->118 dropped 242 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 16->242 244 Found many strings related to Crypto-Wallets (likely being stolen) 16->244 246 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 16->246 250 2 other signatures 16->250 31 cmd.exe 1 16->31         started        33 rundll32.exe 13 16->33         started        35 msedge.exe 18->35         started        37 firefox.exe 18->37         started        41 2 other processes 18->41 248 Hides that the sample has been downloaded from the Internet (zone.identifier) 20->248 file6 signatures7 process8 dnsIp9 98 C:\Users\user\AppData\Local\...\ksvBdSME.exe, PE32+ 22->98 dropped 100 C:\Users\user\AppData\Local\Temp\del.bat, DOS 22->100 dropped 216 Multi AV Scanner detection for dropped file 22->216 218 Self deletion via cmd or bat file 22->218 43 cmd.exe 22->43         started        45 cmd.exe 22->45         started        166 aware-cr1.com 104.21.43.241, 443, 49787 CLOUDFLARENET-CloudflareIncUS Canada 26->166 168 www.youtube.com 26->168 102 C:\Users\user\AppData\Roaming\...\s0907.exe, PE32+ 26->102 dropped 220 Creates an undocumented autostart registry key 26->220 222 Creates multiple autostart registry keys 26->222 224 Drops PE files to the startup folder 26->224 236 5 other signatures 26->236 58 2 other processes 26->58 170 vog.akasia988.net 104.21.7.141, 443, 49790 CLOUDFLARENET-CloudflareIncUS Canada 29->170 226 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 29->226 228 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 29->228 230 Tries to harvest and steal ftp login credentials 29->230 232 Unusual module load detection (module proxying) 31->232 47 bd1b32ab.exe 3 31->47         started        51 conhost.exe 31->51         started        172 239.255.255.250 unknown ZZ 35->172 104 C:\Users\user\AppData\Local\...\Login Data, SQLite 35->104 dropped 106 C:\Users\user\AppData\Local\...\History, SQLite 35->106 dropped 234 Maps a DLL or memory area into another process 35->234 60 3 other processes 35->60 53 firefox.exe 37->53         started        108 C:\Users\user\AppData\Local\Temp\...\21.tmp, PE32 39->108 dropped 56 21.tmp 39->56         started        62 4 other processes 39->62 file10 signatures11 process12 dnsIp13 64 ksvBdSME.exe 43->64         started        68 conhost.exe 43->68         started        83 2 other processes 45->83 122 C:\Users\user\windowsruntime.exe, PE32 47->122 dropped 124 C:\Users\user\...\WindowsSecurityScanner.xml, XML 47->124 dropped 186 Multi AV Scanner detection for dropped file 47->186 188 Drops PE files to the user root directory 47->188 70 cmd.exe 1 47->70         started        72 windowsruntime.exe 47->72         started        152 151.101.65.91 FASTLY-FastlyIncUS Canada 53->152 154 142.251.157.4 GOOGLE-GoogleLLCUS United States 53->154 162 9 other IPs or domains 53->162 126 C:\Users\user\AppData\...\gmpopenh264.dll.tmp, PE32+ 53->126 dropped 128 C:\Users\user\...\gmpopenh264.dll (copy), PE32+ 53->128 dropped 130 C:\Users\user\AppData\...\places.sqlite, SQLite 53->130 dropped 132 C:\Users\user\AppData\...\cookies.sqlite, SQLite 53->132 dropped 74 firefox.exe 53->74         started        134 C:\Users\user\AppData\Local\...\_setup64.tmp, PE32+ 56->134 dropped 136 C:\Users\user\AppData\Local\...\_isdecmp.dll, PE32 56->136 dropped 190 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 56->190 192 Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes) 56->192 76 conhost.exe 58->76         started        78 conhost.exe 58->78         started        156 ln-0007.ln-msedge.net 150.171.22.17 MICROSOFT-CORP-MSN-AS-BLOCK-MicrosoftCorporationUS United States 60->156 158 ax-0002.ax-msedge.net 150.171.27.11 MICROSOFT-CORP-MSN-AS-BLOCK-MicrosoftCorporationUS United States 60->158 164 25 other IPs or domains 60->164 138 C:\Users\user\AppData\Local\...\Cookies, SQLite 60->138 dropped 160 192.168.2.4, 443, 49738, 49765 unknown unknown 62->160 80 chrome.exe 62->80         started        file14 signatures15 process16 dnsIp17 94 C:\Users\user\AppData\...\kgcfpwwuwdrd.exe, PE32+ 64->94 dropped 194 Multi AV Scanner detection for dropped file 64->194 196 Modifies the context of a thread in another process (thread injection) 64->196 198 Adds a directory exclusion to Windows Defender 64->198 202 3 other signatures 64->202 85 powershell.exe 64->85         started        200 Uses schtasks.exe or at.exe to add and modify task schedules 70->200 88 conhost.exe 70->88         started        90 schtasks.exe 1 70->90         started        140 youtube.com 142.250.188.14 GOOGLE-GoogleLLCUS United States 80->140 142 mobile-gtalk.l.google.com 142.250.31.188 GOOGLE-GoogleLLCUS United States 80->142 144 8 other IPs or domains 80->144 96 Chrome Cache Entry: 647, PDP-11 80->96 dropped file18 signatures19 process20 signatures21 214 Loading BitLocker PowerShell Module 85->214 92 conhost.exe 85->92         started        process22
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 64 Exe x64
Threat name:
Win64.Trojan.Vidar
Status:
Malicious
First seen:
2026-08-01 05:03:38 UTC
File Type:
PE+ (Exe)
AV detection:
14 of 24 (58.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  5/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of NtSetInformationThreadHideFromDebugger
Unpacked files
SH256 hash:
aa3ec6bd662f64b5471ba79945d9e620adb66cae5e2887e44eea03d8abc99c73
MD5 hash:
7b0e7c8cc9ca514381a6bfecf879b650
SHA1 hash:
e1c1a8a9d67b3dc8cdce7f357dedf81cfe360ec1
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:pe_no_import_table
Description:Detect pe file that no import table

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Amadey

Executable exe aa3ec6bd662f64b5471ba79945d9e620adb66cae5e2887e44eea03d8abc99c73

(this sample)

Comments