🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2c7b182b19b4dd99edc3c7272abbdc0cf73df6ccdf5ca3d852d2fcf7cd8f2e05. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Vidar


Vendor detections: 12


Intelligence 12 IOCs YARA 1 File information Comments

SHA256 hash: 2c7b182b19b4dd99edc3c7272abbdc0cf73df6ccdf5ca3d852d2fcf7cd8f2e05
SHA3-384 hash: 8170a4bc1305f3165375095b623a39045e0a16ca054d05ba313f2dd6a0dd2dc25fb8732c5e21feace7cce7beff45d8dd
SHA1 hash: e4ccdb226f3a2657140702bd4cc3348659f477f1
MD5 hash: 3d2debbfcd7317c0f8fb17a87107165b
humanhash: mississippi-mobile-arizona-twelve
File name:3e26157a7c88e34cfed41c1e0ee85c93
Download: download sample
Signature Vidar
File size:1'406'464 bytes
First seen:2026-09-21 13:51:23 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
ssdeep 12288:woLKCkX/GfvwKkDycYENT0Qez8VGTXw7HMB6+9:JKVPGnw/Dq2HMn
TLSH T11255FC8FD49213B5B382F7B3822AD6225DF6354584728631DF697E354F03E24A129FCA
TrID 51.9% (.EXE) Win64 Executable (generic) (6522/11/2)
16.1% (.EXE) OS/2 Executable (generic) (2029/13)
15.9% (.EXE) Generic Win/DOS Executable (2002/3)
15.9% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
Reporter abuse_ch
Tags:exe upx-dec vidar


Avatar
abuse_ch
UPX decompressed file, sourced from SHA256 c4869285d769d9449bbaf0071878ac22491eefc59ee43269e50b26d2d3e22dcf
File size (compressed) :370'176 bytes
File size (de-compressed) :1'406'464 bytes
Format:win64/pe
Packed file: c4869285d769d9449bbaf0071878ac22491eefc59ee43269e50b26d2d3e22dcf

Intelligence


File Origin
# of uploads :
1
# of downloads :
210
Origin country :
NL NL
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
No threats detected
Analysis date:
2026-09-21 13:57:01 UTC
Tags:
telegram

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a window
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context microsoft_visual_cc packed
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-09-19T14:58:00Z UTC
Last seen:
2026-09-21T20:23:00Z UTC
Hits:
~1000
Gathering data
Result
Threat name:
Detection:
malicious
Classification:
troj.spyw.evad.mine
Score:
100 / 100
Signature
Allocates memory in foreign processes
Antivirus detection for dropped file
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Contains functionality to inject code into remote processes
Early bird code injection technique detected
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Found strings related to Crypto-Mining
Joe Sandbox ML detected suspicious sample
Monitors registry run keys for changes
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file contains section with special chars
Queues an APC in another process (thread injection)
Suricata IDS alerts for network traffic
Tries to detect sandboxes / dynamic malware analysis system (registry check)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect virtualization through RDTSC time measurements
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Uses the Windows Restart Manager Abuse for Browser Credential File unlocking
Writes to foreign memory regions
Yara detected AntiVM3
Yara detected Vidar stealer
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1975550 Sample: 3e26157a7c88e34cfed41c1e0ee... Startdate: 21/09/2026 Architecture: WINDOWS Score: 100 63 royalcuts.co.uk 2->63 65 nw.1betasia.org 2->65 67 2 other IPs or domains 2->67 95 Suricata IDS alerts for network traffic 2->95 97 Found malware configuration 2->97 99 Antivirus detection for URL or domain 2->99 101 8 other signatures 2->101 8 3e26157a7c88e34cfed41c1e0ee85c93.exe 16 21 2->8         started        13 msedge.exe 3 57 2->13         started        15 msedge.exe 2->15         started        17 4 other processes 2->17 signatures3 process4 dnsIp5 69 royalcuts.co.uk 173.254.56.14, 443, 49793, 49794 ORACLE-BMC-31898-OracleCorporationUS United States 8->69 71 nw.1betasia.org 172.67.201.129, 443, 49714, 49781 CLOUDFLARENET-CloudflareIncUS Canada 8->71 73 telegram.me 149.154.167.99, 443, 49713 TELEGRAMVG United Kingdom 8->73 55 C:\ProgramData\3f8bfc52b9\f43c2226.exe, PE32+ 8->55 dropped 57 C:\ProgramData\3f8bfc52b9\dd3b2b40.exe, PE32+ 8->57 dropped 59 C:\ProgramData\3f8bfc52b9\5c05e262.exe, PE32+ 8->59 dropped 105 Early bird code injection technique detected 8->105 107 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 8->107 109 Found many strings related to Crypto-Wallets (likely being stolen) 8->109 111 11 other signatures 8->111 19 msedge.exe 2 9 8->19         started        22 msedge.exe 8->22         started        24 msedge.exe 8->24         started        31 8 other processes 8->31 75 239.255.255.250 unknown ZZ 13->75 26 msedge.exe 13->26         started        33 2 other processes 13->33 35 4 other processes 15->35 29 msedge.exe 17->29         started        37 5 other processes 17->37 file6 signatures7 process8 dnsIp9 103 Monitors registry run keys for changes 19->103 39 msedge.exe 19->39         started        41 msedge.exe 22->41         started        43 msedge.exe 24->43         started        77 mr-z01.tm-azurefd.net 150.171.109.182, 443, 49740 MICROSOFT-CORP-MSN-AS-BLOCK-MicrosoftCorporationUS South Africa 26->77 83 7 other IPs or domains 26->83 79 150.171.109.178, 443, 49754 MICROSOFT-CORP-MSN-AS-BLOCK-MicrosoftCorporationUS South Africa 29->79 85 6 other IPs or domains 29->85 45 chrome.exe 31->45         started        49 firefox.exe 31->49         started        51 msedge.exe 31->51         started        53 msedge.exe 31->53         started        87 3 other IPs or domains 35->87 81 150.171.109.184, 443, 49770, 49771 MICROSOFT-CORP-MSN-AS-BLOCK-MicrosoftCorporationUS South Africa 37->81 89 4 other IPs or domains 37->89 signatures10 process11 dnsIp12 91 www.google.com 142.251.151.119, 443, 49722, 49730 GOOGLE-GoogleLLCUS United States 45->91 61 Chrome Cache Entry: 212, PDP-11 45->61 dropped 93 127.0.0.1 unknown unknown 49->93 file13
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 64 Exe x64
Threat name:
Win64.Trojan.Egairtigado
Status:
Malicious
First seen:
2026-09-19 19:53:28 UTC
File Type:
PE+ (Exe)
AV detection:
20 of 24 (83.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Unpacked files
SH256 hash:
2c7b182b19b4dd99edc3c7272abbdc0cf73df6ccdf5ca3d852d2fcf7cd8f2e05
MD5 hash:
3d2debbfcd7317c0f8fb17a87107165b
SHA1 hash:
e4ccdb226f3a2657140702bd4cc3348659f477f1
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:pe_no_import_table
Description:Detect pe file that no import table

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Vidar

Executable exe 2c7b182b19b4dd99edc3c7272abbdc0cf73df6ccdf5ca3d852d2fcf7cd8f2e05

(this sample)

Comments