Suspicious 80% vxunderground-inthewild Download

2026-04-09_7e49a496f443288614493d429578d6eb_amadey_darkgate_elex_rhadamanthys_smoke-loader_stop

Stolen Adobe cert, malware names

Authenticode chain CN: Adobe Systems, IncorporatedAuthenticode chain CN: Microsoft Corporation
SHA-2562de99042fdb2faec32d46545bdce3d81d3bd9d3c657066794e1c2ad9d71a7554

Evidence

Embedded PE binary at file offset 0x121066 (~192712 bytes) 0x121026–0x1210f6
⋯3 more rows
0x121056beb4011e584cc5bf5c6a000000000000....XL..\j......
0x1210664d5a90000300000004000000ffff0000MZ..............
0x121076b8000000000000004000000000000000........@.......
0x12108600000000000000000000000000000000................
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.