🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f4e29cc8122b6bc3bd14910eae33c15b60059a4ba6145eebdb59090649e07fb0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Amadey


Vendor detections: 15


Intelligence 15 IOCs YARA 4 File information Comments

SHA256 hash: f4e29cc8122b6bc3bd14910eae33c15b60059a4ba6145eebdb59090649e07fb0
SHA3-384 hash: 909bbfc677bdec5848fc0f7a82dd21ca487a678573cf2a14bcdd2eea01566fdeb83a03acb6ec82658336686fdd7318a1
SHA1 hash: a78993894b694dc64b235fcd416071efbe4c8a1e
MD5 hash: 6560523a5f58a5ec460399be504365bb
humanhash: stairway-delaware-princess-venus
File name:file
Download: download sample
Signature Amadey
File size:847'360 bytes
First seen:2026-05-07 17:01:39 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 835e7131fceb7b369597efbebd85dc9d (2 x Vidar, 1 x Amadey)
ssdeep 24576:CP134HzWJZncEGahYFQw6UOMc7YN8GAR:CEzgnceeOM8YSG
TLSH T1F1059F119FD352EAEC334939D4EA131B68F47CD882A08E33C6670E993D43565B33B666
TrID 33.1% (.EXE) Win64 Executable (generic) (6522/11/2)
25.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
10.4% (.ICL) Windows Icons Library (generic) (2059/9)
10.3% (.EXE) OS/2 Executable (generic) (2029/13)
10.1% (.EXE) Generic Win/DOS Executable (2002/3)
Magika pebin
Reporter abuse_ch
Tags:Amadey exe upx-dec


Avatar
abuse_ch
UPX decompressed file, sourced from SHA256 527c99c63beca1735ed785e3907aa7c88a467453a4a55f808400e8e402e6cbe3
File size (compressed) :522'240 bytes
File size (de-compressed) :847'360 bytes
Format:win64/pe
Packed file: 527c99c63beca1735ed785e3907aa7c88a467453a4a55f808400e8e402e6cbe3

Intelligence


File Origin
# of uploads :
1
# of downloads :
228
Origin country :
NL NL
Vendor Threat Intelligence
No detections
Malware family:
ID:
1
File name:
_f4e29cc8122b6bc3bd14910eae33c15b60059a4ba6145eebdb59090649e07fb0.exe
Verdict:
Malicious activity
Analysis date:
2026-05-07 17:03:04 UTC
Tags:
stealer stealc vidar amadey botnet nircmd tool unlocker-eject saked dropper upx auto-reg credentialflusher

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Gathering data
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
DNS request
Connection attempt
Behavior that indicates a threat
Sending a custom TCP request
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug fingerprint packed
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-05-06T15:52:00Z UTC
Last seen:
2026-05-08T20:38:00Z UTC
Hits:
~10
Detections:
UDS:DangerousObject.Multi.Generic
Gathering data
Result
Threat name:
Amadey, Vidar
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
Allocates memory in foreign processes
Antivirus detection for dropped file
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Contains functionality to check if a debugger is running (CheckRemoteDebuggerPresent)
Creates a thread in another existing process (thread injection)
Creates multiple autostart registry keys
Drops password protected ZIP file
Drops PE files to the user root directory
Early bird code injection technique detected
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Hides threads from debuggers
Joe Sandbox ML detected suspicious sample
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Queues an APC in another process (thread injection)
Sample uses string decryption to hide its real strings
Sigma detected: New RUN Key Pointing to Suspicious Folder
Suricata IDS alerts for network traffic
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect virtualization through RDTSC time measurements
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Uses cmd line tools excessively to alter registry or file data
Uses schtasks.exe or at.exe to add and modify task schedules
Uses the nircmd tool (NirSoft)
Windows shortcut file (LNK) contains suspicious command line arguments
Writes to foreign memory regions
Yara detected Amadey
Yara detected Amadeys Clipper DLL
Yara detected Vidar stealer
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1910249 Sample: file.exe Startdate: 07/05/2026 Architecture: WINDOWS Score: 100 97 bik.hidayahnetwork.com 2->97 99 www3.l.google.com 2->99 101 34 other IPs or domains 2->101 117 Suricata IDS alerts for network traffic 2->117 119 Found malware configuration 2->119 121 Antivirus detection for URL or domain 2->121 123 12 other signatures 2->123 12 taskmanager.exe 2 38 2->12         started        17 file.exe 1 2 2->17         started        signatures3 process4 dnsIp5 107 196.251.107.248, 49737, 49741, 49743 ANGANI-ASKE Seychelles 12->107 87 C:\Users\user\AppData\...\c71af72dd0.exe, PE32+ 12->87 dropped 89 C:\Users\user\AppData\...\0715dd4849.exe, PE32 12->89 dropped 91 C:\Users\user\AppData\Local\...\M94scZj.exe, PE32+ 12->91 dropped 95 11 other malicious files 12->95 dropped 155 Antivirus detection for dropped file 12->155 157 Multi AV Scanner detection for dropped file 12->157 159 Creates multiple autostart registry keys 12->159 19 b23c9ddd37.exe 13 12->19         started        23 CEqsnUi.exe 12->23         started        25 KAQ8PQ5.exe 12->25         started        109 bik.hidayahnetwork.com 104.21.20.183, 443, 49716, 49720 CLOUDFLARENETUS United States 17->109 111 62.60.226.140, 49735, 49742, 49744 ASLINE-AS-APASLINELIMITEDHK Iran (ISLAMIC Republic Of) 17->111 113 telegram.me 149.154.167.99, 443, 49715, 49751 TELEGRAMRU United Kingdom 17->113 93 C:\Users\user\AppData\Local\...\4cdf7175.exe, PE32 17->93 dropped 161 Early bird code injection technique detected 17->161 163 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 17->163 165 Found many strings related to Crypto-Wallets (likely being stolen) 17->165 167 7 other signatures 17->167 28 cmd.exe 1 17->28         started        30 firefox.exe 5 17->30         started        32 msedge.exe 7 17->32         started        34 chrome.exe 1 17->34         started        file6 signatures7 process8 dnsIp9 77 C:\Users\user\AppData\Local\...\nircmd.exe, PE32+ 19->77 dropped 79 C:\Users\user\AppData\Local\...\cecho.exe, PE32 19->79 dropped 81 C:\Users\user\AppData\Local\Temp\...\7z.exe, PE32 19->81 dropped 125 Multi AV Scanner detection for dropped file 19->125 36 cmd.exe 19->36         started        127 Tries to harvest and steal browser information (history, passwords, etc) 23->127 129 Tries to detect virtualization through RDTSC time measurements 23->129 131 Hides threads from debuggers 23->131 133 Creates a thread in another existing process (thread injection) 23->133 103 steamcommunity.com 23.214.233.226, 443, 49755, 49763 RELIANCEJIO-INRelianceJioInfocommLimitedIN United States 25->103 105 hor.kaitorinihon.jp 172.67.193.26, 443, 49765 CLOUDFLARENETUS United States 25->105 135 Contains functionality to check if a debugger is running (CheckRemoteDebuggerPresent) 25->135 137 Uses cmd line tools excessively to alter registry or file data 28->137 39 4cdf7175.exe 10 28->39         started        42 conhost.exe 28->42         started        44 firefox.exe 17 30->44         started        file10 signatures11 process12 dnsIp13 139 Uses cmd line tools excessively to alter registry or file data 36->139 47 nircmd.exe 36->47         started        49 conhost.exe 36->49         started        51 nircmd.exe 36->51         started        58 2 other processes 36->58 83 C:\Users\user\taskmanager.exe, PE32 39->83 dropped 85 C:\Users\...\SystemConfigurationManager.xml, XML 39->85 dropped 141 Antivirus detection for dropped file 39->141 143 Multi AV Scanner detection for dropped file 39->143 145 Drops PE files to the user root directory 39->145 53 cmd.exe 1 39->53         started        56 taskmanager.exe 39->56         started        115 127.0.0.1 unknown unknown 44->115 file14 signatures15 process16 signatures17 60 cmd.exe 47->60         started        147 Uses cmd line tools excessively to alter registry or file data 53->147 149 Uses schtasks.exe or at.exe to add and modify task schedules 53->149 151 Uses the nircmd tool (NirSoft) 53->151 63 conhost.exe 53->63         started        65 schtasks.exe 1 53->65         started        process18 signatures19 153 Uses cmd line tools excessively to alter registry or file data 60->153 67 cmd.exe 60->67         started        69 conhost.exe 60->69         started        71 nircmd.exe 60->71         started        73 14 other processes 60->73 process20 process21 75 tasklist.exe 67->75         started       
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 64 Exe x64
Threat name:
Win64.Packed.Generic
Status:
Suspicious
First seen:
2026-05-06 20:02:02 UTC
File Type:
PE+ (Exe)
AV detection:
8 of 24 (33.33%)
Threat level:
  1/5
Verdict:
malicious
Label(s):
Similar samples:
Result
Malware family:
n/a
Score:
  10/10
Tags:
credential_access discovery spyware stealer
Behaviour
Checks processor information in registry
Enumerates system info in registry
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Browser Information Discovery
System Time Discovery
Drops file in Windows directory
Suspicious use of NtSetInformationThreadHideFromDebugger
Checks installed software on the system
Reads WinSCP keys stored on the system
Reads data files stored by FTP clients
Reads user/profile data of web browsers
Unsecured Credentials: Credentials In Files
Suspicious use of NtCreateProcessExOtherParentProcess
Unpacked files
SH256 hash:
f4e29cc8122b6bc3bd14910eae33c15b60059a4ba6145eebdb59090649e07fb0
MD5 hash:
6560523a5f58a5ec460399be504365bb
SHA1 hash:
a78993894b694dc64b235fcd416071efbe4c8a1e
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:telebot_framework
Author:vietdx.mb
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Amadey

Executable exe f4e29cc8122b6bc3bd14910eae33c15b60059a4ba6145eebdb59090649e07fb0

(this sample)

Comments