Threat name:
Amadey, CryptOne, GCleaner, REMUS Steale
Alert
Classification:
spre.phis.troj.spyw.expl.evad
Adds a directory exclusion to Windows Defender
AI detected malicious Powershell script
AI detected suspicious PE / MSI digital signature
Allocates memory in foreign processes
C2 URLs / IPs found in malware configuration
Contains functionality to inject code into remote processes
Creates a thread in another existing process (thread injection)
Drops executables to the windows directory (C:\Windows) and starts them
Found direct / indirect Syscall (likely to bypass EDR)
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Hides that the sample has been downloaded from the Internet (zone.identifier)
Hijacks the control flow in another process
Icon mismatch, binary includes an icon from a different legit application in order to fool users
Injects a PE file into a foreign processes
Injects code into the Windows Explorer (explorer.exe)
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Overwrites code with unconditional jumps - possibly settings hooks in foreign process
Powershell creates an autostart link
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sample uses string decryption to hide its real strings
Sigma detected: Potential Startup Shortcut Persistence Via PowerShell.EXE
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Powershell create lnk in startup
Sigma detected: Suspicious Script Execution From Temp Folder
Suricata IDS alerts for network traffic
Suspicious access to claude desktop data directory by non-Claude process
Suspicious powershell command line found
System process connects to network (likely due to code injection or exploit)
Tries to detect sleep reduction / modifications
Tries to detect virtualization through RDTSC time measurements
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to steal Crypto Currency Wallets
Tries to steal from password manager
Tries to steal Instant Messenger accounts or passwords
Tries to steal Mail credentials (via file / registry access)
Unusual module load detection (module proxying)
Writes to foreign memory regions
Yara detected Amadeys Clipper DLL
Yara detected CryptOne packer
Yara detected defendnot Loader
Yara detected REMUS Stealer
Yara detected UAC Bypass using CMSTP
behaviorgraph
top1
dnsIp2
2
Behavior Graph
ID:
1977689
Sample:
file.exe
Startdate:
24/09/2026
Architecture:
WINDOWS
Score:
100
150
45.91.200.135
PODAONLV
Netherlands
2->150
152
185.156.73.98
FDN3UA
Netherlands
2->152
154
6 other IPs or domains
2->154
180
Suricata IDS alerts
for network traffic
2->180
182
Found malware configuration
2->182
184
Malicious sample detected
(through community Yara
rule)
2->184
186
21 other signatures
2->186
12
file.exe
2->12
started
15
defendnot-loader.exe
2->15
started
17
msiexec.exe
2->17
started
20
AdvDefragConsole.exe
2->20
started
signatures3
process4
dnsIp5
240
Overwrites code with
unconditional jumps
- possibly settings
hooks in foreign process
12->240
242
Hijacks the control
flow in another process
12->242
244
Contains functionality
to inject code into
remote processes
12->244
256
2 other signatures
12->256
23
svchost.exe
49
12->23
started
246
Writes to foreign memory
regions
15->246
248
Allocates memory in
foreign processes
15->248
250
Creates a thread in
another existing process
(thread injection)
15->250
28
Taskmgr.exe
15->28
started
98
C:\Windows\Installer\MSIDF7E.tmp, PE32
17->98
dropped
100
C:\...\fleetdeck_agent_svc.exe, PE32
17->100
dropped
30
fleetdeck_agent_svc.exe
17->30
started
32
msiexec.exe
17->32
started
164
94.26.38.30
OMEGATECH-ASSC
Netherlands
20->164
252
Multi AV Scanner detection
for dropped file
20->252
254
Unusual module load
detection (module proxying)
20->254
file6
signatures7
process8
dnsIp9
166
91.92.242.236, 49754, 80
OMEGATECH-ASSC
Netherlands
23->166
168
drive.usercontent.google.com
142.250.191.1, 443, 49750
GOOGLE-GoogleLLCUS
United States
23->168
112
C:\Users\user\AppData\...\wdPk4QyvZ.exe, PE32+
23->112
dropped
114
C:\Users\user\AppData\...\6uPR5sQQXQmp.exe, PE32+
23->114
dropped
116
C:\Users\user\AppData\...\3ZfGUjn1tnRUo.exe, PE32+
23->116
dropped
118
15 other malicious files
23->118
dropped
234
System process connects
to network (likely due
to code injection or
exploit)
23->234
236
Unusual module load
detection (module proxying)
23->236
34
QWqljroTQX7e.exe
2
23->34
started
38
uPUatgMkFSa.exe
23->38
started
40
RgRNuPckj.exe
2
23->40
started
44
11 other processes
23->44
238
Suspicious powershell
command line found
30->238
42
powershell.exe
30->42
started
file10
signatures11
process12
dnsIp13
104
C:\Users\user\AppData\...\QWqljroTQX7e.tmp, PE32
34->104
dropped
188
Multi AV Scanner detection
for dropped file
34->188
47
QWqljroTQX7e.tmp
18
26
34->47
started
190
Injects code into the
Windows Explorer (explorer.exe)
38->190
192
Writes to foreign memory
regions
38->192
194
Allocates memory in
foreign processes
38->194
206
2 other signatures
38->206
50
explorer.exe
38->50
injected
196
Suspicious powershell
command line found
40->196
198
Adds a directory exclusion
to Windows Defender
40->198
54
RgRNuPckj.exe
40->54
started
56
conhost.exe
40->56
started
58
conhost.exe
42->58
started
170
ip-api.com
208.95.112.1
TUT-AS-TotalUptimeTechnologiesLLCUS
United States
44->170
172
nailgalleryapp.com
196.41.127.31
CybersmartZA
South Africa
44->172
174
3 other IPs or domains
44->174
106
C:\Users\user\AppData\...\Hl0iKKdMFw.tmp, PE32
44->106
dropped
108
C:\Users\user\...\25BFBBA00FD79F17.exe, PE32+
44->108
dropped
110
C:\Users\user\AppData\...\6uPR5sQQXQmp.exe, PE32+
44->110
dropped
200
Queries sensitive video
device information (via
WMI, Win32_VideoController,
often done to detect
virtual machines)
44->200
202
Tries to steal Mail
credentials (via file
/ registry access)
44->202
204
Found many strings related
to Crypto-Wallets (likely
being stolen)
44->204
208
8 other signatures
44->208
60
Hl0iKKdMFw.tmp
44->60
started
62
conhost.exe
44->62
started
file14
signatures15
process16
dnsIp17
120
C:\Users\user\AppData\Local\...\_shfoldr.dll, PE32
47->120
dropped
122
C:\Users\user\AppData\Local\...\_setup64.tmp, PE32+
47->122
dropped
124
C:\Users\user\AppData\Local\...\_iscrypt.dll, PE32
47->124
dropped
134
21 other malicious files
47->134
dropped
64
AdvDefragConsole.exe
25
47->64
started
156
ksakdakd1k.club
172.67.158.137
CLOUDFLARENET-CloudflareIncUS
Canada
50->156
210
System process connects
to network (likely due
to code injection or
exploit)
50->210
212
Tries to steal Instant
Messenger accounts or
passwords
50->212
214
Tries to steal Mail
credentials (via file
/ registry access)
50->214
222
5 other signatures
50->222
68
chrome.exe
50->68
started
126
C:\Windows\lq0CRFNh\defendnot.dll, PE32+
54->126
dropped
128
C:\Windows\lq0CRFNh\defendnot-loader.exe, PE32+
54->128
dropped
136
2 other malicious files
54->136
dropped
216
Suspicious powershell
command line found
54->216
218
Drops executables to
the windows directory
(C:\Windows) and
starts them
54->218
220
Adds a directory exclusion
to Windows Defender
54->220
70
defendnot-loader.exe
54->70
started
73
powershell.exe
54->73
started
75
powershell.exe
54->75
started
77
2 other processes
54->77
130
C:\Users\user\AppData\Local\...\_setup64.tmp, PE32+
60->130
dropped
132
C:\Users\user\AppData\Local\...\_isdecmp.dll, PE32
60->132
dropped
file18
signatures19
process20
dnsIp21
142
94.26.38.17
OMEGATECH-ASSC
Netherlands
64->142
144
196.251.121.77
Hero-TelecomsZA
Germany
64->144
146
64.89.160.142
GHOSTYNETWORKSUS
Luxembourg
64->146
102
C:\ProgramData\...\AdvDefragConsole.exe, PE32
64->102
dropped
79
powershell.exe
17
64->79
started
148
192.168.2.5, 443, 49750, 49751
unknown
unknown
68->148
83
chrome.exe
68->83
started
224
Multi AV Scanner detection
for dropped file
70->224
226
Writes to foreign memory
regions
70->226
228
Allocates memory in
foreign processes
70->228
230
Creates a thread in
another existing process
(thread injection)
70->230
86
Taskmgr.exe
70->86
started
232
Loading BitLocker PowerShell
Module
73->232
88
conhost.exe
73->88
started
90
conhost.exe
75->90
started
92
conhost.exe
77->92
started
94
Conhost.exe
77->94
started
file22
signatures23
process24
dnsIp25
138
C:\Users\user\...\fAdvDefragConsole32.lnk, MS
79->138
dropped
176
Found many strings related
to Crypto-Wallets (likely
being stolen)
79->176
178
Powershell creates an
autostart link
79->178
96
conhost.exe
79->96
started
158
www.google.com
142.251.154.119
GOOGLE-GoogleLLCUS
United States
83->158
160
mobile-gtalk.l.google.com
142.251.167.188
GOOGLE-GoogleLLCUS
United States
83->160
162
4 other IPs or domains
83->162
140
Chrome Cache Entry: 362, PDP-11
83->140
dropped
file26
signatures27
process28
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.