Online Virus Checker | v.1.0.140.174 |
DB Version: | 2023-09-30 12:04:05 |
Amadey is a formidable Windows infostealer threat, characterized by its persistence mechanisms, modular design, and ability to execute various malicious tasks. It typically infiltrates systems through phishing emails or malicious downloads. Once inside a system, Amadey can capture sensitive information such as login credentials, personal data, and financial details. Its modular structure allows threat actors to customize its functionality, making it a versatile tool in cybercriminal arsenals.
Checked | 2023-09-30 09:12:21 |
MD5 | 9f49123510046b22057757564152923e |
SHA1 | ee42364ed3921df79c0644770cf1d9b1f3c81111 |
SHA256 | 89514d80ee5134e867e90052275abdd3e78cd50bf3c593784c73ef3f95cb94b7 |
SHA512 | 57b42530327b9e14038bec81a8c14361ff6c73910e6d0d65ff6a829c789e5cb2a67051169b894e33e1788ffb8f85f09e8e9c824b9182b8facd91194bdd355c15 |
Imphash | 96baacc90461fcd4b5d9fcc50047c098 |
File Size | 251904 bytes |
Gridinsoft has the capability to identify and eliminate Trojan.Win32.Amadey.bot without requiring further user intervention.
Image Base: | 0x00400000 |
Entry Point: | 0x00409d63 |
Compilation: | 2023-09-30 08:32:39 |
Checksum: | 0x00000000 (Actual: 0x0004a6ee) |
OS Version: | 6.0 |
PEiD: | PE32 executable (console) Intel 80386, for MS Windows |
Sign: | The PE file does not contain a certificate table. |
Sections: | 4 |
Imports: | ADVAPI32, KERNEL32, |
Exports: | 1 |
Resources: | 0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Entropy |
---|---|---|---|---|---|
.text | 0x00001000 | 0x00025744 | 0x00025800 | ff699f056dadb8ddf9451705744e59d4 | 6.76 |
.rdata | 0x00027000 | 0x0000d78a | 0x0000d800 | 014bde9285442671f00bf79d33642c55 | 5.56 |
.data | 0x00035000 | 0x00009634 | 0x00008800 | 83aabf1f6b0786660b9e7cad945aeb7a | 7.62 |
.reloc | 0x0003f000 | 0x00001b28 | 0x00001c00 | 88ee7da3a3bb459a450cdfceb9a34503 | 6.47 |