🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 21601d0599caec1184ef1ca0314dfdd1b270cc8a9fe7aa9efc8e142f46ba0281. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Vidar


Vendor detections: 13


Intelligence 13 IOCs YARA 4 File information Comments

SHA256 hash: 21601d0599caec1184ef1ca0314dfdd1b270cc8a9fe7aa9efc8e142f46ba0281
SHA3-384 hash: 5f293c78941544bc868db0754ba7bb009d076e4b019a81b4f3c0afe09f8c2082699e79fe5622267582145fc65d1ee602
SHA1 hash: 26cf6fe8e0a2851d67c40f09cdda6fc87a5f943d
MD5 hash: 0274499a696714551fbfb93585dd3ce3
humanhash: winter-may-six-early
File name:SecuriteInfo.com.Win32.MalwareX-gen.26728.32078
Download: download sample
Signature Vidar
File size:1'137'664 bytes
First seen:2025-05-29 14:24:52 UTC
Last seen:2025-05-29 15:18:37 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'238 x AgentTesla, 20'488 x Formbook, 12'372 x SnakeKeylogger)
ssdeep 12288:56X6CYc4FcO5PbwquX45ELm/glIxA7NkXbI37qgPGIyT3JkWECa1:xCYckEqKLXIxV2qg+IaEC
TLSH T16135CF5523D8A904F67F2BF05470E5A043B3B8CA9876D32D068C85EE2F73751AA92763
TrID 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
10.2% (.EXE) Win64 Executable (generic) (10522/11/4)
6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.3% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
dhash icon 631cf3c68b33e3e6 (2 x Rhadamanthys, 2 x LummaStealer, 2 x DarkTortilla)
Reporter SecuriteInfoCom
Tags:exe vidar

Intelligence


File Origin
# of uploads :
2
# of downloads :
681
Origin country :
FR FR
Vendor Threat Intelligence
Malware family:
ID:
1
File name:
SecuriteInfo.com.Win32.MalwareX-gen.26728.32078
Verdict:
Malicious activity
Analysis date:
2025-05-29 14:25:49 UTC
Tags:
httpdebugger tool telegram vidar stealer

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
DNS request
Сreating synchronization primitives
Connection attempt
Sending a custom TCP request
Sending an HTTP GET request
Creating a window
Launching a process
Unauthorized injection to a system process
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
cmd lolbin obfuscated obfuscated reconnaissance vbnet
Result
Threat name:
Detection:
malicious
Classification:
troj.spyw.expl.evad
Score:
100 / 100
Signature
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
.NET source code contains process injector
.NET source code references suspicious native API functions
Compiles code for process injection (via .Net compiler)
Creates a thread in another existing process (thread injection)
Encrypted powershell cmdline option found
Found direct / indirect Syscall (likely to bypass EDR)
Hides that the sample has been downloaded from the Internet (zone.identifier)
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sigma detected: Dot net compiler compiles file from suspicious location
Suricata IDS alerts for network traffic
Switches to a custom stack to bypass stack traces
Tries to harvest and steal browser information (history, passwords, etc)
Uses threadpools to delay analysis
Writes to foreign memory regions
Yara detected AntiVM3
Yara detected Powershell decode and execute
Yara detected Vidar stealer
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1701571 Sample: SecuriteInfo.com.Win32.Malw... Startdate: 29/05/2025 Architecture: WINDOWS Score: 100 92 xx.7.4t.com 2->92 94 x.ns.gin.ntt.net 2->94 96 18 other IPs or domains 2->96 126 Suricata IDS alerts for network traffic 2->126 128 Malicious sample detected (through community Yara rule) 2->128 130 Multi AV Scanner detection for submitted file 2->130 132 9 other signatures 2->132 10 SecuriteInfo.com.Win32.MalwareX-gen.26728.32078.exe 15 3 2->10         started        signatures3 process4 dnsIp5 104 i.ibb.co 207.174.26.219, 443, 49681, 49692 RCN-ASUS United States 10->104 90 SecuriteInfo.com.W...26728.32078.exe.log, ASCII 10->90 dropped 142 Writes to foreign memory regions 10->142 144 Hides that the sample has been downloaded from the Internet (zone.identifier) 10->144 146 Injects a PE file into a foreign processes 10->146 148 Uses threadpools to delay analysis 10->148 15 AddInProcess32.exe 33 10->15         started        19 AddInProcess32.exe 14 3 10->19         started        21 AddInProcess32.exe 10->21         started        file6 signatures7 process8 dnsIp9 110 xx.7.4t.com 78.46.235.75, 443, 49695, 49696 HETZNER-ASDE Germany 15->110 112 t.me 149.154.167.99, 443, 49694 TELEGRAMRU United Kingdom 15->112 114 Encrypted powershell cmdline option found 15->114 116 Tries to harvest and steal browser information (history, passwords, etc) 15->116 23 powershell.exe 15->23         started        27 chrome.exe 15->27         started        30 powershell.exe 15->30         started        34 25 other processes 15->34 118 Hides that the sample has been downloaded from the Internet (zone.identifier) 19->118 120 Injects a PE file into a foreign processes 19->120 32 AddInProcess32.exe 19->32         started        122 Uses threadpools to delay analysis 21->122 124 Switches to a custom stack to bypass stack traces 21->124 signatures10 process11 dnsIp12 86 C:\Users\user\AppData\...\xu0tupat.cmdline, Unicode 23->86 dropped 134 Writes to foreign memory regions 23->134 136 Compiles code for process injection (via .Net compiler) 23->136 138 Creates a thread in another existing process (thread injection) 23->138 36 csc.exe 23->36         started        39 conhost.exe 23->39         started        106 192.168.2.7, 123, 138, 14433 unknown unknown 27->106 41 chrome.exe 27->41         started        88 C:\Users\user\AppData\Local\...\oedzwaj5.0.cs, Unicode 30->88 dropped 44 conhost.exe 30->44         started        108 77.110.125.28, 14433, 49727, 49754 STSSA Lebanon 32->108 140 Found direct / indirect Syscall (likely to bypass EDR) 32->140 46 csc.exe 34->46         started        48 csc.exe 34->48         started        50 csc.exe 34->50         started        52 20 other processes 34->52 file13 signatures14 process15 dnsIp16 70 C:\Users\user\AppData\Local\...\xu0tupat.dll, PE32 36->70 dropped 54 cvtres.exe 36->54         started        98 ogads-pa.clients6.google.com 142.250.113.95, 443, 49721, 49722 GOOGLEUS United States 41->98 100 plus.l.google.com 142.250.114.102, 443, 49720 GOOGLEUS United States 41->100 102 3 other IPs or domains 41->102 72 C:\Users\user\AppData\Local\...\1hp3cek0.dll, PE32 46->72 dropped 56 cvtres.exe 46->56         started        74 C:\Users\user\AppData\Local\...\zxljmdxn.dll, PE32 48->74 dropped 58 cvtres.exe 48->58         started        76 C:\Users\user\AppData\Local\...\ajdtiaop.dll, PE32 50->76 dropped 60 cvtres.exe 50->60         started        78 C:\Users\user\AppData\Local\...\x02uyt0a.dll, PE32 52->78 dropped 80 C:\Users\user\AppData\Local\...\ngcfdoiz.dll, PE32 52->80 dropped 82 C:\Users\user\AppData\Local\...\mvt2jrz3.dll, PE32 52->82 dropped 84 5 other files (none is malicious) 52->84 dropped 62 cvtres.exe 52->62         started        64 cvtres.exe 52->64         started        66 cvtres.exe 52->66         started        68 5 other processes 52->68 file17 process18
Threat name:
Win32.Trojan.Egairtigado
Status:
Malicious
First seen:
2025-05-29 14:25:22 UTC
File Type:
PE (.Net Exe)
Extracted files:
41
AV detection:
19 of 24 (79.17%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:vidar botnet:489c25ffabb35a36a7aac6fb3c16f04b credential_access defense_evasion discovery spyware stealer
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies data under HKEY_USERS
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Browser Information Discovery
Program crash
System Location Discovery: System Language Discovery
Drops file in Windows directory
Suspicious use of SetThreadContext
Accesses cryptocurrency files/wallets, possible credential harvesting
Obfuscated Files or Information: Command Obfuscation
Unsecured Credentials: Credentials In Files
Uses browser remote debugging
Detect Vidar Stealer
Vidar
Vidar family
Malware Config
C2 Extraction:
https://t.me/w0d0lm
https://steamcommunity.com/profiles/76561199860669882
Verdict:
Informative
Tags:
n/a
YARA:
n/a
Unpacked files
SH256 hash:
21601d0599caec1184ef1ca0314dfdd1b270cc8a9fe7aa9efc8e142f46ba0281
MD5 hash:
0274499a696714551fbfb93585dd3ce3
SHA1 hash:
26cf6fe8e0a2851d67c40f09cdda6fc87a5f943d
Malware family:
Rhadamanthys
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (GUARD_CF)high

Comments