Survival Trojan Amadey Analysis

Trojan Amadey
Updated on 2024-03-02 (3 months ago)
Checked by Online Virus Scanner
Online Virus Checkerv.1.0.168.174
DB Version:2024-03-02 05:00:24

Trojan.Win32.Amadey.tr

Amadey is a formidable Windows infostealer threat, characterized by its persistence mechanisms, modular design, and ability to execute various malicious tasks. It typically infiltrates systems through phishing emails or malicious downloads. Once inside a system, Amadey can capture sensitive information such as login credentials, personal data, and financial details. Its modular structure allows threat actors to customize its functionality, making it a versatile tool in cybercriminal arsenals.

FileSurvival
Checked2024-03-02 03:38:51
MD5117a962cde2568514649b76a004190f1
SHA1e92ab6267e005eb78bac3c13b9de881b726bc7f2
SHA2568dec86d0a0c4034b6d688a0610742694517e0d31939c53db11b898c0ba7315c0
SHA512a2eb2cd551bea8eead2cc7cf17dd91849395c475f329e9bd47ff4ebab8aff0c9a1e33921e4fc6af9ca762b6c80c48056b8991f8813b7e19a7eca4dfb0914041d
Imphasha24ea59447df74f26ce8c1567f650e9c
File Size265728 bytes

Trojan.Win32.Amadey.tr Removal

Trojan.Win32.Amadey.tr Removal

Gridinsoft has the capability to identify and eliminate Trojan.Win32.Amadey.tr without requiring further user intervention.

  • Start by downloading Gridinsoft Anti-Malware to your computer.
  • Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  • Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  • Click on the "Standard Scan" button.
  • After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  • If prompted, restart your system to complete the removal process.

File Version Information

FileVersions53.15.14.94
FileDescriptionGun
OriginalFilenameSurvival
ProductNameCircuz
ProductVersion1.0.2.1
Translation0x0409 0x04e4

Portable Executable Info

f52b798d231756a7e508151f340526d7
584c4b0b9000b332fac39ab21ad3f1df
c8a48484aca494e0
Image Base:0x00400000
Entry Point:0x004028f8
Compilation:2022-12-04 17:18:35
Checksum:0x0004e4a5 (Actual: 0x0004e4a5)
OS Version:5.0
PDB Path:C:\zariho\fayuwovawot\kimimiviriwej\fetekovafu-ronacutas90\m.pdb
PEiD:PE32 executable (GUI) Intel 80386, for MS Windows
Sign:The PE file does not contain a certificate table.
Sections:4
Imports: KERNEL32, USER32, ADVAPI32,
Exports: 0
Resources:22

Sections

Name Virtual Address Virtual Size Raw Size MD5 Entropy
.text 0x00001000 0x00025ed0 0x00026000 54677d37e6663b861fc473d55ac2d14c 7.60
.rdata 0x00027000 0x00005370 0x00005400 5956ba18fbb28031cc0f666aa096dcd9 5.80
.data 0x0002d000 0x015f3da0 0x0000a200 f501ce68cffc724ea252e994295cdbd7 0.68
.rsrc 0x01621000 0x0000b2a0 0x0000b400 db2a1afa878ff5970d739034ff5ade46 4.55

Leave a comment*

Share your thoughts or insights about this file. Do you align with our conclusion?

*Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Please Wait...

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware