Login for search help

Payload Details

First Seen 2026-02-24 (Login for timestamps)
Last Seen 2026-03-03
SHA256 9450c8f5fb17a1faf510d3ed6ce78430b103ce4e54474e5f50a53c5cf9b414d3
Filetype PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
Size 443,904 bytes
Distributed By Vidar (Login)
Countries Unknown Country Login for country information
UnpacMe ID 8f164f57-c269-4a71-a05d-9f72aaa20b38
UnpacMe Detections MALWARE:AmadeyTYPE:DOWNLOADERRULE:AmadeyCONFIG:Amadey
UnpacMe Community RULE:win_amadey_auto
Sandbox Detections AmadeyGCleaner
Malcat Kesakode One of the process dumps is 35% similar to GCleanerGCleaner 35%
Download

Monitored Sandbox Execution

Login required

Non-Monitored Sandbox Execution

Login required

Tasks of Origin (60)

First Seen (UTC) Last Seen (UTC) Family Botnet Exit Task Data View
2026-03-022026-03-04vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-03-012026-03-04vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-03-012026-03-04vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-03-012026-03-04vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-03-012026-03-04vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-03-012026-03-04vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-282026-03-06vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-272026-03-06vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-272026-03-06vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-272026-03-06vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-272026-03-06vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-272026-03-06vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-212026-03-06vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-212026-03-06vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-212026-03-06vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-212026-03-06vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-212026-03-06vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-212026-03-06vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-062026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-062026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-062026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-062026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-062026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-062026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-042026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-042026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-042026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-042026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-042026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-042026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-032026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-032026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-032026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-032026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-032026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-032026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-032026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-032026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-032026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-032026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-032026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-02-032026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-01-312026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-01-312026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-01-312026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-01-312026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-01-312026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-01-312026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-01-312026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-01-312026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-01-312026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-01-312026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-01-312026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-01-312026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-01-312026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-01-312026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-01-312026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-01-312026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-01-312026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe
2026-01-312026-02-26vidarLogin
Unknown Country
http://130.12.180.43/amka/random.exe