Online Virus Checker | v.1.0.136.174 |
DB Version: | 2023-09-09 00:04:35 |
Amadey is a formidable Windows infostealer threat, characterized by its persistence mechanisms, modular design, and ability to execute various malicious tasks. It typically infiltrates systems through phishing emails or malicious downloads. Once inside a system, Amadey can capture sensitive information such as login credentials, personal data, and financial details. Its modular structure allows threat actors to customize its functionality, making it a versatile tool in cybercriminal arsenals.
File | Wextract |
Checked | 2023-09-08 21:13:20 |
MD5 | 1d2e8e7d687189eb17bd74a69f1362f2 |
SHA1 | 0fce57d67740da3e8ffe44000c05d87540e0aa3a |
SHA256 | 4d5f90b294e9020f1d38798c0b59c461b2e88d03492a8644003422f004630e8f |
SHA512 | bd1aeb8c0c6138b6e0252c7aedeaded9f74ec818c8dd6f7e184438d36c6b73aadee99cba00bedf0766a9828dcbaa50258f454026832f802565e50be3abc1a5bc |
Imphash | 646167cce332c1c252cdcb1839e0cf48 |
File Size | 721920 bytes |
Gridinsoft has the capability to identify and eliminate Trojan.Win32.Amadey.bot without requiring further user intervention.
CompanyName | Microsoft Corporation |
FileDescription | Win32 Cabinet Self-Extractor |
FileVersion | 11.00.17763.1 (WinBuild.160101.0800) |
InternalName | Wextract |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | WEXTRACT.EXE .MUI |
ProductName | Internet Explorer |
ProductVersion | 11.00.17763.1 |
Translation | 0x0409 0x04b0 |
3e91cc67e146308239c15a39134ff14e 2e2cf0d16805fb9dfdfc9b2658485b99 f0f0f4d8c8c8d8f0 |
|
Image Base: | 0x00400000 |
Entry Point: | 0x00406a60 |
Compilation: | 2022-05-24 22:49:06 |
Checksum: | 0x000b3647 (Actual: 0x000b3647) |
OS Version: | 10.0 |
PDB Path: | wextract.pdb |
PEiD: | - |
Sign: | The PE file does not contain a certificate table. |
Sections: | 5 |
Imports: | ADVAPI32, KERNEL32, GDI32, USER32, msvcrt, COMCTL32, Cabinet, VERSION, |
Exports: | 0 |
Resources: | 43 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Entropy |
---|---|---|---|---|---|
.text | 0x00001000 | 0x00006314 | 0x00006400 | b0b66b32f4ca82e2e157c51b24da0be7 | 6.31 |
.data | 0x00008000 | 0x00001a48 | 0x00000200 | 7b9890a93c0516bb070e1170cfde54d5 | 4.97 |
.idata | 0x0000a000 | 0x00001052 | 0x00001200 | 67ce48bf2e7c8fe3321ca7aa188f77e2 | 5.03 |
.rsrc | 0x0000c000 | 0x000a8000 | 0x000a7e00 | 1ce14fbbf52c7a23df788c868fb4b341 | 7.92 |
.reloc | 0x000b4000 | 0x00000888 | 0x00000a00 | 6025c825c4098ef081ac8ee3c8d5dd22 | 6.22 |