Dayroc.exe Trojan Amadey Analysis

Trojan Amadey
Updated on 2024-02-05 (1 month ago)
Checked by Online Virus Scanner
Online Virus Checkerv.1.0.158.174
DB Version:2024-02-05 20:00:28

Trojan.Win32.Amadey.tr

Amadey is a formidable Windows infostealer threat, characterized by its persistence mechanisms, modular design, and ability to execute various malicious tasks. It typically infiltrates systems through phishing emails or malicious downloads. Once inside a system, Amadey can capture sensitive information such as login credentials, personal data, and financial details. Its modular structure allows threat actors to customize its functionality, making it a versatile tool in cybercriminal arsenals.

Filedayroc.exe
Checked2024-02-05 18:15:51
MD5c4580e8db0c3dbc88891842fd8a31158
SHA1744f03fcf10db1459d3f40beaea2bfe1b000582b
SHA2561f435b3a62304733dce1b9caf24cfac768db739127e8ec31d466455628ec0922
SHA512cefd412e0d5aba56d6603fdc46a056474ce387dbb220b32a9317dca0822bef9320515afacc2ab2086db46f9e01b3456c87a0dc83bd99c246550d87efd3606945
Imphashf34d5f2d4577ed6d9ceec516c1f5a744
File Size5804544 bytes

Trojan.Win32.Amadey.tr Removal

Trojan.Win32.Amadey.tr Removal

Gridinsoft has the capability to identify and eliminate Trojan.Win32.Amadey.tr without requiring further user intervention.

  • Start by downloading Gridinsoft Anti-Malware to your computer.
  • Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  • Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  • Click on the "Standard Scan" button.
  • After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  • If prompted, restart your system to complete the removal process.

File Version Information

Translation0x0000 0x04b0
FileDescription
FileVersion1.0.0.0
InternalNamedayroc.exe
LegalCopyright
OriginalFilenamedayroc.exe
ProductVersion1.0.0.0
Assembly Version1.0.0.0

Portable Executable Info

Image Base:0x00400000
Entry Point:0x0098a70e
Compilation:2024-02-05 10:09:40
Checksum:0x00000000 (Actual: 0x00596b4f)
OS Version:4.0
PEiD:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
Sign:The PE file does not contain a certificate table.
Sections:3
Imports: mscoree,
Exports: 0
Resources:2

Sections

Name Virtual Address Virtual Size Raw Size MD5 Entropy
.text 0x00002000 0x00588714 0x00588800 380cd18ed0dc489b1762d2e254731779 7.89
.rsrc 0x0058c000 0x000004d8 0x00000600 dc108891102f524c9ce41dbd56944003 3.72
.reloc 0x0058e000 0x0000000c 0x00000200 cbc835c36790918f4d84d61e32dce8fd 0.10

Leave a comment*

Share your thoughts or insights about this file. Do you align with our conclusion?

*Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Please Wait...

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware