| File name: | x43750805d5a7c406ce1fbf0508916d9fa14615daf0e99536db50580b89dc73e2.exe |
| Full analysis: | https://app.any.run/tasks/b2dd7b96-3eb4-4566-bcd3-608a2d68e402 |
| Verdict: | Malicious activity |
| Threats: | Amadey is a formidable Windows infostealer threat, characterized by its persistence mechanisms, modular design, and ability to execute various malicious tasks. |
| Analysis date: | May 22, 2026, 23:28:58 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32+ executable (GUI) x86-64, for MS Windows, 7 sections |
| MD5: | 7C5AC7E6472EC54ECE3AD71742FD1DFA |
| SHA1: | 4E04DF49E1EEF2C538E82C1EEB19CDEFF14ACBED |
| SHA256: | 43750805D5A7C406CE1FBF0508916D9FA14615DAF0E99536DB50580B89DC73E2 |
| SSDEEP: | 98304:/kzLPhlAQsUIco+T5QCIjGFlmk1qKE1xU0Wq86qHX827Nq610asRK52blc/E52bv:oFq |
| .exe | | | Win64 Executable (generic) (87.3) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (6.3) |
| .exe | | | DOS Executable Generic (6.3) |
| MachineType: | AMD AMD64 |
|---|---|
| TimeStamp: | 2026:05:22 12:03:59+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware |
| PEType: | PE32+ |
| LinkerVersion: | 14.5 |
| CodeSize: | 50176 |
| InitializedDataSize: | 2610176 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x17cc |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1456 | C:\WINDOWS\system32\notepad.exe | C:\Windows\System32\notepad.exe | h2kn78pg2d.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2164 | "C:\Users\admin\AppData\Roaming\9fo34yipzn.exe" | C:\Users\admin\AppData\Roaming\9fo34yipzn.exe | x43750805d5a7c406ce1fbf0508916d9fa14615daf0e99536db50580b89dc73e2.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2396 | C:\WINDOWS\system32\notepad.exe | C:\Windows\System32\notepad.exe | — | lhxy2lubbf.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2648 | "C:\ProgramData\zboml.exe" | C:\ProgramData\zboml.exe | 9fo34yipzn.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 4172 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4412 | sihost.exe | C:\Windows\System32\sihost.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Shell Infrastructure Host Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4696 | C:\WINDOWS\Explorer.EXE | C:\Windows\explorer.exe | — | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Version: 10.0.19041.3758 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4968 | "C:\Users\admin\Desktop\x43750805d5a7c406ce1fbf0508916d9fa14615daf0e99536db50580b89dc73e2.exe" | C:\Users\admin\Desktop\x43750805d5a7c406ce1fbf0508916d9fa14615daf0e99536db50580b89dc73e2.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 5232 | C:\Windows\System32\RuntimeBroker.exe -Embedding | C:\Windows\System32\RuntimeBroker.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Runtime Broker Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5384 | "C:\Users\admin\AppData\Roaming\5m3jcbdfqp.exe" | C:\Users\admin\AppData\Roaming\5m3jcbdfqp.exe | x43750805d5a7c406ce1fbf0508916d9fa14615daf0e99536db50580b89dc73e2.exe | ||||||||||||
User: admin Company: Synaptics Incorporated Integrity Level: MEDIUM Description: Windows Explorer Version: 8.8.6790.64 Modules
| |||||||||||||||
| (PID) Process: | (1456) notepad.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (1456) notepad.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (1456) notepad.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (5384) 5m3jcbdfqp.exe | Key: | HKEY_CURRENT_USER\Environment |
| Operation: | write | Name: | UserInitMprLogonScript |
Value: "C:\WINDOWS\system32\cmd.exe" /c start /b "" "C:\Users\admin\AppData\Roaming\Microsoft\Windows\Services\winhost.exe" | |||
| (PID) Process: | (4172) slui.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\3d\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\System32\sppcomapi.dll,-3200 |
Value: Software Licensing | |||
| (PID) Process: | (2164) 9fo34yipzn.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | cjahz |
Value: C:\ProgramData\zboml.exe | |||
| (PID) Process: | (2164) 9fo34yipzn.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer |
| Operation: | write | Name: | SlowContextMenuEntries |
Value: 6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000 | |||
| (PID) Process: | (2648) zboml.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (2648) zboml.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (2648) zboml.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4968 | x43750805d5a7c406ce1fbf0508916d9fa14615daf0e99536db50580b89dc73e2.exe | C:\Users\admin\AppData\Roaming\h2kn78pg2d.exe | executable | |
MD5:E3E2E9F305F7A3032592C8F1C31C02BB | SHA256:458EC1F07DF85EB6DB2A204038D6DEE8833F77B0A6A5B8D8BE747F541E56CFE0 | |||
| 4968 | x43750805d5a7c406ce1fbf0508916d9fa14615daf0e99536db50580b89dc73e2.exe | C:\Users\admin\AppData\Roaming\5m3jcbdfqp.exe | executable | |
MD5:AC25FF38A0029649036CBEFD2720F4F0 | SHA256:B2FB627F2AFD9009EE0B2662BE278357BD17F27F0F8F91957DB3EB956951C011 | |||
| 5384 | 5m3jcbdfqp.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Services\winhost.exe | executable | |
MD5:AC25FF38A0029649036CBEFD2720F4F0 | SHA256:B2FB627F2AFD9009EE0B2662BE278357BD17F27F0F8F91957DB3EB956951C011 | |||
| 4968 | x43750805d5a7c406ce1fbf0508916d9fa14615daf0e99536db50580b89dc73e2.exe | C:\Users\admin\AppData\Roaming\lhxy2lubbf.exe | executable | |
MD5:7CAC2FF04CE6C44CD955E3AB6976D6A0 | SHA256:C5FA429F91A93161413C960E0CBF2ACEC608D6DF09C45A5B21F5B6ACD512B591 | |||
| 4968 | x43750805d5a7c406ce1fbf0508916d9fa14615daf0e99536db50580b89dc73e2.exe | C:\Users\admin\AppData\Roaming\9fo34yipzn.exe | executable | |
MD5:90D500EE74FB78CE02BAA06E890EF9AE | SHA256:E9670B3D82A74F2E4B8C8F342CED0C04E32CACEE495490C62F1B1573CDA60B52 | |||
| 4968 | x43750805d5a7c406ce1fbf0508916d9fa14615daf0e99536db50580b89dc73e2.exe | C:\Users\admin\Desktop\SilverBulletPro1.exe | executable | |
MD5:D3117E8306C159F218D9409843F3A9F3 | SHA256:08785C9711CFF3899F8859D6E18DF36DA52776649E892CA2EA4E5318035FCE2F | |||
| 2164 | 9fo34yipzn.exe | C:\ProgramData\zboml.exe | executable | |
MD5:90D500EE74FB78CE02BAA06E890EF9AE | SHA256:E9670B3D82A74F2E4B8C8F342CED0C04E32CACEE495490C62F1B1573CDA60B52 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4348 | SIHClient.exe | GET | 304 | 74.178.76.128:443 | https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL | US | — | — | whitelisted |
4348 | SIHClient.exe | GET | 200 | 74.178.76.54:443 | https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping | US | — | — | whitelisted |
7984 | svchost.exe | GET | 200 | 2.16.241.19:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | NL | binary | 825 b | whitelisted |
7984 | svchost.exe | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | US | binary | 814 b | whitelisted |
4348 | SIHClient.exe | GET | 200 | 74.178.76.128:443 | https://slscr.update.microsoft.com/sls/ping | US | — | — | whitelisted |
4348 | SIHClient.exe | GET | 304 | 74.178.76.128:443 | https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL | US | — | — | whitelisted |
5384 | 5m3jcbdfqp.exe | POST | 200 | 62.60.226.159:80 | http://62.60.226.159/api.php | GB | — | — | unknown |
2648 | zboml.exe | POST | 200 | 62.60.226.159:80 | http://62.60.226.159/xvzpjyddlu/getdata.php | GB | — | — | malicious |
5384 | 5m3jcbdfqp.exe | POST | 200 | 62.60.226.159:80 | http://62.60.226.159/api.php | GB | — | — | unknown |
4348 | SIHClient.exe | GET | 304 | 74.178.76.128:443 | https://slscr.update.microsoft.com/SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL | US | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | Not routed | — | whitelisted |
— | — | 48.209.138.168:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
5276 | MoUsoCoreWorker.exe | 48.209.138.168:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
7312 | slui.exe | 128.24.231.65:443 | activation-v2.sls.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4 | System | 192.168.100.255:138 | — | Not routed | — | whitelisted |
7984 | svchost.exe | 2.16.241.19:80 | crl.microsoft.com | AKAMAI-ASN1 | NL | whitelisted |
7984 | svchost.exe | 88.221.169.152:80 | www.microsoft.com | AKAMAI-AS | US | whitelisted |
7984 | svchost.exe | 48.209.6.48:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
5276 | MoUsoCoreWorker.exe | 48.209.6.48:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
5384 | 5m3jcbdfqp.exe | 62.60.226.159:80 | — | FEMOIT | GB | malicious |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
activation-v2.sls.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |
login.live.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
5384 | 5m3jcbdfqp.exe | Misc Attack | ET DROP Spamhaus DROP Listed Traffic Inbound group 9 |
1456 | notepad.exe | Misc Attack | ET DROP Spamhaus DROP Listed Traffic Inbound group 45 |
2648 | zboml.exe | Misc activity | INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0) |
2648 | zboml.exe | A Network Trojan was detected | MALWARE [ANY.RUN] Win32/Amadey associated URI (/xvzpjyddlu/getdata.php) |
1456 | notepad.exe | A Network Trojan was detected | MALWARE [ANY.RUN] Win32/Stealc stealer activity observed |
2648 | zboml.exe | Misc activity | INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0) |
2648 | zboml.exe | A Network Trojan was detected | MALWARE [ANY.RUN] Win32/Amadey associated URI (/xvzpjyddlu/getdata.php) |
2648 | zboml.exe | Misc activity | INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0) |
2648 | zboml.exe | A Network Trojan was detected | MALWARE [ANY.RUN] Win32/Amadey associated URI (/xvzpjyddlu/getdata.php) |
Process | Message |
|---|---|
SilverBulletPro1.exe | The application to execute does not exist: 'C:\Users\admin\Desktop\SilverBulletPro.dll'. |