MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 22b165bcac09ae6033ad71038128a62b29ca787d5a51ebab926f016b7926f84e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Vidar


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 22b165bcac09ae6033ad71038128a62b29ca787d5a51ebab926f016b7926f84e
SHA3-384 hash: 32849a18b584f0d276b795f22a183dbf4682e6b227790479cbe9133790aeaf574f18fc99dd0328716e447b9254c9d950
SHA1 hash: 86c06740e0b15aabfcbfaeaeee7b3493f0745e8d
MD5 hash: 318d7fef2e959476c5fe199716b97d9c
humanhash: carolina-six-pasta-low
File name:Ev[3]-Bop0[t]2.zip
Download: download sample
Signature Vidar
File size:11'308'266 bytes
First seen:2026-02-27 08:23:16 UTC
Last seen:Never
File type: zip
MIME type:application/zip
Note:This file is a password protected archive. The password is: 1709
ssdeep 196608:mvk3WpC+HInEgtOtXaeN11ouofyBbbMUcw+xfnZ1YiGNfxDKzkeQjDMo:m8mbHIEsOv1sUchxWiGNfpCkeQ3Mo
TLSH T182B633C4A3B897756F74B816C203FBE74745B2568A353C696357320613C39AA0CB1FAE
TrID 66.6% (.WIDGET) Konfabulator widget (8000/1/2)
33.3% (.ZIP) ZIP compressed archive (4000/1)
Magika zip
Reporter burger
Tags:pw-1709 vidar zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
NL NL
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Ev[3]-Bop0[t].zip
File size:11'308'989 bytes
SHA256 hash: b6047e32db3223f4473f584292b5386fb742eacac645f57872dc26f5396059a8
MD5 hash: f0c728acab121962325b10e9f4a7fadc
MIME type:application/zip
Signature Vidar
Vendor Threat Intelligence
Gathering data
Result
Malware family:
Score:
  10/10
Tags:
family:vidar discovery persistence privilege_escalation stealer
Behaviour
Detects Vidar Stealer
Vidar
Vidar family
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments