Login for search help

Payload Details

First Seen 2026-02-20 (Login for timestamps)
Last Seen 2026-02-23
SHA256 73268ba4f02818b8597b585147be43155afd621fa098eec72d1a3c4e7d341a31
Filetype PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
Size 442,368 bytes
Distributed By Vidar (Login)
Countries Unknown Country Login for country information
UnpacMe ID 7b7bd176-8723-47c1-aee2-0a11eca763f9
UnpacMe Detections MALWARE:AmadeyTYPE:DOWNLOADERRULE:AmadeyCONFIG:Amadey
UnpacMe Community RULE:win_amadey_auto
Sandbox Detections AmadeyGCleanerCoinMiner
Malcat Kesakode One of the process dumps is 26% similar to VidarVidar 26%One of the process dumps is 35% similar to GCleanerGCleaner 35%
Download

Monitored Sandbox Execution

Login required

Non-Monitored Sandbox Execution

Login required

Tasks of Origin (49)

First Seen (UTC) Last Seen (UTC) Family Botnet Exit Task Data View
2026-02-212026-03-06vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-212026-03-06vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-212026-03-06vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-212026-03-06vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-212026-03-06vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-212026-03-06vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-202026-02-20vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-062026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-062026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-062026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-062026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-062026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-062026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-042026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-042026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-042026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-042026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-042026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-042026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-032026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-032026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-032026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-032026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-032026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-032026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-032026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-032026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-032026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-032026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-032026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-032026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-01-312026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-01-312026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-01-312026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-01-312026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-01-312026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-01-312026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-01-312026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-01-312026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-01-312026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-01-312026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-01-312026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-01-312026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-01-312026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-01-312026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-01-312026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-01-312026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-01-312026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-01-312026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe