MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e85149704da6ee8f9bc1c55304c560d1a792180489d4859a64cf0a4e056ccf52. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Amadey


Vendor detections: 15


Intelligence 15 IOCs 2 YARA 12 File information Comments

SHA256 hash: e85149704da6ee8f9bc1c55304c560d1a792180489d4859a64cf0a4e056ccf52
SHA3-384 hash: 38bb14e6c381d318d9a55f39e7bc6158d33f033d79409177329d31836fcddf02c411dbcc289d018f400ba18fde761e79
SHA1 hash: 16646bfd7f6554cd170fb373ce813c24f37e829e
MD5 hash: f8e68cddf13a94d821a4b265172a0e32
humanhash: artist-romeo-johnny-bulldog
File name:F8E68CDDF13A94D821A4B265172A0E32.exe
Download: download sample
Signature Amadey
File size:640'000 bytes
First seen:2026-07-19 23:45:09 UTC
Last seen:2026-07-20 08:55:35 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash cd702dbfbd74cf5a80f59195b2460134 (4 x Stealc, 1 x Amadey)
ssdeep 12288:L7bqVdZJ9HO5ov7zbrjr2RMh+luyxBlDetAqxSvwiA:L7evcojzbqRM+luyb4i
TLSH T1A4D4C013B9A18476E1724635CD68EB54977DBC700F20ABCB67C005AA6EB06C0AF37767
TrID 41.0% (.EXE) InstallShield setup (43053/19/16)
29.7% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
6.2% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.2% (.EXE) Win64 Executable (generic) (6522/11/2)
4.7% (.EXE) Win16 NE executable (generic) (5038/12/1)
Magika pebin
Reporter abuse_ch
Tags:Amadey exe


Avatar
abuse_ch
Amadey C2:
http://196.251.107.186/qK3mRv9L/pLdWr.php

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
http://196.251.107.186/qK3mRv9L/pLdWr.php https://threatfox.abuse.ch/ioc/1853971/
http://192.162.199.186/aB7xTy2N/mAjOR.php https://threatfox.abuse.ch/ioc/1853972/

Intelligence


File Origin
# of uploads :
2
# of downloads :
243
Origin country :
NL NL
Vendor Threat Intelligence
No detections
Malware family:
ID:
1
File name:
d78cdf00b2e3afce7efe2ec7eea42904
Verdict:
Malicious activity
Analysis date:
2026-07-17 10:00:20 UTC
Tags:
telegram maskgram stealer auto maskgramstealer generic solaris loader stealc nuitka payload python amadey botnet

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.9%
Tags:
autorun emotet cobalt spoof
Result
Verdict:
Clean
Maliciousness:

Behaviour
Сreating synchronization primitives
Connecting to a non-recommended domain
Connection attempt
Sending an HTTP POST request
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
adaptive-context anti-debug base64 crypto evasive fingerprint loader microsoft_visual_cc overlay stealc
Verdict:
Malicious
Labled as:
Shellcode.Loader.Marte.X.Generic
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-07-16T17:48:00Z UTC
Last seen:
2026-07-21T12:58:00Z UTC
Hits:
~100
Result
Threat name:
Clipboard Hijacker, Stealc v2
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
Allocates memory in foreign processes
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Antivirus detection for URL or domain
Changes the view of files in windows explorer (hidden files and folders)
Creates a thread in another existing process (thread injection)
Found direct / indirect Syscall (likely to bypass EDR)
Found many strings related to Crypto-Wallets (likely being stolen)
Hides that the sample has been downloaded from the Internet (zone.identifier)
Injects a PE file into a foreign processes
Injects code into the Windows Explorer (explorer.exe)
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Switches to a custom stack to bypass stack traces
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Crypto Currency Wallets
Uses schtasks.exe or at.exe to add and modify task schedules
Writes to foreign memory regions
Yara detected Clipboard Hijacker
Yara detected Stealc v2
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1944901 Sample: Wz8Xn63q02.exe Startdate: 20/07/2026 Architecture: WINDOWS Score: 100 72 Malicious sample detected (through community Yara rule) 2->72 74 Antivirus detection for URL or domain 2->74 76 Antivirus / Scanner detection for submitted sample 2->76 78 4 other signatures 2->78 8 Wz8Xn63q02.exe 83 2->8         started        13 metdz.exe 2->13         started        15 winhost.exe 2->15         started        process3 dnsIp4 66 192.162.199.186, 49770, 49777, 49790 FEMOITGB United Kingdom 8->66 68 196.251.107.163, 49761, 80 FEMOITGB Germany 8->68 60 C:\Users\user\AppData\...\tOd4RpWT02GC.exe, PE32+ 8->60 dropped 62 C:\Users\user\AppData\...\WNFqlfeLdhnE.exe, PE32+ 8->62 dropped 64 C:\Users\user\AppData\...\5z2yzXEBw9gF.exe, PE32+ 8->64 dropped 98 Found many strings related to Crypto-Wallets (likely being stolen) 8->98 100 Tries to harvest and steal browser information (history, passwords, etc) 8->100 102 Writes to foreign memory regions 8->102 116 3 other signatures 8->116 17 tOd4RpWT02GC.exe 2 2 8->17         started        21 5z2yzXEBw9gF.exe 1 7 8->21         started        23 WNFqlfeLdhnE.exe 4 8->23         started        27 6 other processes 8->27 104 Antivirus detection for dropped file 13->104 106 Multi AV Scanner detection for dropped file 13->106 108 Injects code into the Windows Explorer (explorer.exe) 13->108 25 schtasks.exe 13->25         started        70 196.251.107.186, 49771, 49772, 49773 FEMOITGB Germany 15->70 110 Allocates memory in foreign processes 15->110 112 Creates a thread in another existing process (thread injection) 15->112 114 Injects a PE file into a foreign processes 15->114 file5 signatures6 process7 file8 54 C:\Users\user\AppData\Roaming\...\winhost.exe, PE32+ 17->54 dropped 80 Antivirus detection for dropped file 17->80 82 Multi AV Scanner detection for dropped file 17->82 84 Changes the view of files in windows explorer (hidden files and folders) 17->84 92 4 other signatures 17->92 29 sihost.exe 17->29 injected 31 RuntimeBroker.exe 17->31 injected 46 3 other processes 17->46 56 C:\Users\user\AppData\Roaming\...\metdz.exe, PE32+ 21->56 dropped 86 Injects code into the Windows Explorer (explorer.exe) 21->86 88 Uses schtasks.exe or at.exe to add and modify task schedules 21->88 90 Writes to foreign memory regions 21->90 33 schtasks.exe 1 21->33         started        35 schtasks.exe 1 21->35         started        37 schtasks.exe 1 21->37         started        39 explorer.exe 2 1 21->39 injected 58 C:\Users\user\AppData\Local\...\ncstvs.exe, PE32+ 23->58 dropped 41 ncstvs.exe 23->41         started        44 conhost.exe 25->44         started        signatures9 process10 signatures11 48 conhost.exe 33->48         started        50 conhost.exe 35->50         started        52 conhost.exe 37->52         started        94 Antivirus detection for dropped file 41->94 96 Multi AV Scanner detection for dropped file 41->96 process12
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout Win 32 Exe x86
Threat name:
Win32.Trojan.StealC
Status:
Malicious
First seen:
2026-07-16 21:22:56 UTC
File Type:
PE (Exe)
Extracted files:
1
AV detection:
29 of 38 (76.32%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:amadey family:stealc botnet:292234 discovery execution persistence spyware stealer trojan
Behaviour
Uses Task Scheduler COM API
Checks processor information in registry
Enumerates system info in registry
Modifies data under HKEY_USERS
Modifies registry class
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious behavior: LoadsDriver
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of UnmapMainImage
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
System Time Discovery
Drops file in Windows directory
Accesses cryptocurrency files/wallets, possible credential harvesting
Adds Run key to start application
Checks installed software on the system
Checks computer location settings
Executes dropped EXE
Reads WinSCP keys stored on the system
Reads user/profile data of web browsers
Downloads MZ/PE file
Sets service image path in registry
Detects Stealc stealer Version 2
Family: Amadey
Family: Stealc
Malware Config
C2 Extraction:
http://196.251.107.186
http://192.162.199.186
Unpacked files
SH256 hash:
e85149704da6ee8f9bc1c55304c560d1a792180489d4859a64cf0a4e056ccf52
MD5 hash:
f8e68cddf13a94d821a4b265172a0e32
SHA1 hash:
16646bfd7f6554cd170fb373ce813c24f37e829e
Detections:
win_stealc_auto
SH256 hash:
61ab1d22949eac0582e989ae065ec4caee9ac99998276317edda96735cd311fb
MD5 hash:
a8480ece517b8367ca8418d7888f410d
SHA1 hash:
49802c5598b2e9d94229ae987d0ac47bbf8977ea
Detections:
win_stealc_auto
Parent samples :
84bd20bcb88426402c4a3c96d8012396f83387a84b7abc1a6e90c2babebb42bd
b91cebec72ba934cde8ee67e8c4135c8c558d8ff46a70d3fdca83d9c37dd377b
290e9e54d6ff86cb4afc7acbbf10a06ed10f3fe476768dc96129a2a715208330
abb513eaa060b22c139fef518ba9b45785acd317ea6e01a945df346c9564eff7
764936d39ec0d9e3e00e04db2d6d3acc61b6bf77412ddc67ce180d6fbf665f58
fb924e8cef93d0a4244790ba1e1a4ecaf1a93b19f8e816329cdd763b017df459
bf24277400cc453d530e4277d3bd24e96c5e409adef6970518bdc59205aa0241
9a7c87d58a7ab1f2d99c5390d04c3875e41587b46f0632518e6108286ca45e2c
711199755fc55ac8185e64fe03bcc07aade1d449bd30e4bf7b898436d6eb3685
0215f734867bd71c57ff5c524d8cc670be5b4f1861b2c390cf46d18784a53624
efe7eb517cc449cc7721c5c0acfb8cf454f28fdf2f37c08854aad4deefd7edc9
1217681270b058cb08ff0eef8aad93219db13db2162a528d99267a354a85e62a
0f97b6a0c25560d63a863ff043a9556cb730ed6c8b20916eac98e2b969ab5f48
b7060387c40d51ac08a6e7ce33226b02f975ccfdc8ffa95c7412110e4adbe855
d5cad85a993f432900438b0b241f62226f2709cc7d2a0ab6897f58009eb4d670
1188d1f47cfc3797e1eb004e531b11b7a191a21475d97226dfa607db380b650b
dd0bebc17d103b682c00e5cc6f92ae28432a357cc9f9fc49f1747d28931c6402
9fe5f01662010999236f92b351ef36a759a58421fa4bca630c17e35e8cf8e0d9
354d3dc2b8997764925d5c42ee1c87acb4ba0bdca257edb7a2e63f53a4678c5c
526abca3f813871d7e2930c99bbe9c1d6a660cb7e6624e65e54154e4e3cf897d
252653fff0e5c8ce66326b2f105dcb74a728c76d78991773e385fa580c0833cf
e85149704da6ee8f9bc1c55304c560d1a792180489d4859a64cf0a4e056ccf52
80b64331aab73ae1cb476c6a1dbe804abf304fded3d52303a700524e8370c92b
018cff3b8d3d9ecd0cdff35222c83d0859933652f5b368246a8641d96fa7154c
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:HeavensGate
Author:kevoreilly
Description:Heaven's Gate: Switch from 32-bit to 64-mode
Rule name:Heuristics_ChromeABE
Author:Still
Description:attempts to match instructions related to Chrome App-bound Encryption elevation service; possibly spotted amongst infostealers
Rule name:malware_shellcode_hash
Author:JPCERT/CC Incident Response Group
Description:detect shellcode api hash value
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.
Rule name:Windows_Trojan_Stealc_df3cdc7e
Author:Elastic Security
Rule name:win_stealc_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.stealc.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments