🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e50c4c2f36e9f0fbac79f1609e92df749b54be1e0d6d5970c4a4ca397d8e9569. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Amadey


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: e50c4c2f36e9f0fbac79f1609e92df749b54be1e0d6d5970c4a4ca397d8e9569
SHA3-384 hash: 08bd1250cd34c7113cf49931a5f714f827abfd51583bf40b09d8fa42afa634dd8fc448ade2d3e6707081328e27d325c3
SHA1 hash: 03044d9cfab861e9842f07c95f3b0d12b9d19502
MD5 hash: 7352929908929ad0aca013fcfc7584d0
humanhash: hot-twenty-chicken-nineteen
File name:SETUP.zip
Download: download sample
Signature Amadey
File size:20'511'369 bytes
First seen:2026-03-26 13:25:09 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 393216:RosDgDJL23mZE7jx3UyzlSGl0eWsdZ26OEh5/iu4FoR5SNQSYs1s1As1O9kZbqnI:RpcDB2WZEPptHFhViuSoku1s1sWsMqUI
TLSH T1B8273318E93D1744C89F7F389EBC48A3E6B0C3198A77B71DDA1415C82CD3670AB62E16
TrID 46.6% (.SH3D) Sweet Home 3D Design (generic) (10500/1/3)
35.5% (.XPI) Mozilla Firefox browser extension (8000/1/1)
17.7% (.ZIP) ZIP compressed archive (4000/1)
Magika zip
Reporter aachum
Tags:ACRStealer Amadey dllHijack kl-wholeunfrosted-cfd zip


Avatar
iamaachum
https://winssoft.org/ => https://mega.nz/file/8nBVmIAA#-OVZKG1cmvdh---_EedfPudCSyMb12F4as6nJACtnOI

ACRStealer C2: kl.wholeunfrosted.cfd

Intelligence


File Origin
# of uploads :
1
# of downloads :
242
Origin country :
ES ES
Vendor Threat Intelligence
Verdict:
Suspicious
Score:
50%
Tags:
infosteal
Verdict:
Malicious
File Type:
zip
First seen:
2026-03-25T12:29:00Z UTC
Last seen:
2026-03-26T14:42:00Z UTC
Hits:
~10
Gathering data
Gathering data
Threat name:
Win32.Trojan.Ropalidia
Status:
Malicious
First seen:
2026-03-25 19:29:44 UTC
File Type:
Binary (Archive)
Extracted files:
1083
AV detection:
14 of 24 (58.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  5/10
Tags:
discovery
Behaviour
Suspicious behavior: EnumeratesProcesses
Program crash
System Location Discovery: System Language Discovery
Suspicious use of NtSetInformationThreadHideFromDebugger
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Amadey

zip e50c4c2f36e9f0fbac79f1609e92df749b54be1e0d6d5970c4a4ca397d8e9569

(this sample)

  
Delivery method
Distributed via web download

Comments