🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2df2599e1f1e5555723ebf783deed130702a1f3484f82d7fa2a4963507b57382. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Vidar


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 2df2599e1f1e5555723ebf783deed130702a1f3484f82d7fa2a4963507b57382
SHA3-384 hash: b6bd49167ef5b136fec2f36f04bdfd6b88196f87a5b584b7028163af53de3a91d78f930d53aa761552afacdff82370e2
SHA1 hash: f4d2d04ca3b422f10806cd83ce0ebc27ae0e80c3
MD5 hash: bb06a8f0af94c96f430132a02e8f4910
humanhash: bluebird-river-hotel-undress
File name:2df2599e1f1e5555723ebf783deed130702a1f3484f82d7fa2a4963507b57382.bin
Download: download sample
Signature Vidar
File size:96'314'480 bytes
First seen:2026-08-24 16:48:16 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 1c1ad2adeb06878a984583db245d2aa2 (24 x Vidar)
ssdeep 1572864:wxkUCeVV5U2nMJtbNf6pSNIeQfcLU4SevDjoHqiVLgYqqqkTEYWZ74:/9Qg2Mb5SsL3N/baVLgYqqqoXx
TLSH T1CC283303B99441A4D4669B31C5BA9353BB35B88E9B3673C33F44A2381F367D06EB9316
TrID 45.6% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
18.0% (.EXE) Win64 Executable (generic) (6522/11/2)
13.9% (.EXE) Win16 NE executable (generic) (5038/12/1)
5.6% (.ICL) Windows Icons Library (generic) (2059/9)
5.6% (.EXE) OS/2 Executable (generic) (2029/13)
Magika pebin
Reporter Anonymous
Tags:exe vidar

Intelligence


File Origin
# of uploads :
1
# of downloads :
156
Origin country :
CH CH
Vendor Threat Intelligence
No detections
Result
Verdict:
Clean
Maliciousness:

Behaviour
Launching the default Windows debugger (dwwin.exe)
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug anti-vm base64 bloated crypto golang masquerade mingw overlay packed vidar
Verdict:
Malicious
File Type:
dll x64
First seen:
2026-08-23T12:34:00Z UTC
Last seen:
2026-08-26T06:55:00Z UTC
Hits:
~100
Gathering data
Threat name:
Win64.Spyware.Vidar
Status:
Malicious
First seen:
2026-08-23 17:20:10 UTC
File Type:
PE+ (Dll)
AV detection:
20 of 38 (52.63%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of NtSetInformationThreadHideFromDebugger
Badlisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments