MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3bd5d67962c2c260a0691c8b209a0d93ef40dddaee9cb048887b1070aa7a02ac. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Vidar


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 3bd5d67962c2c260a0691c8b209a0d93ef40dddaee9cb048887b1070aa7a02ac
SHA3-384 hash: 1eeba743bac983b50414698e043836c1b6bc9b6b446af3a78cee2fb7a7128b5212456943dd954e2574e8b750f21a24e7
SHA1 hash: 9081a09cd22961c2b80f078512205803b3b3dc19
MD5 hash: 4f3f9bb347a2a6d2c5b1f35a677f5777
humanhash: fifteen-lion-carpet-victor
File name:figural.exe
Download: download sample
Signature Vidar
File size:80'793'652 bytes
First seen:2026-08-22 15:45:34 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash b34f154ec913d2d2c435cbd644e91687 (592 x GuLoader, 130 x RemcosRAT, 84 x EpsilonStealer)
ssdeep 1572864:gLdkyV3ivaMYi/iFhXPFIABZI48z2Fi/S8JKBUmy+N5Xe6EfB7B7:g2+3ivsZFh/aABZVPArg/bXeB7B7
TLSH T12D08338047564386C1CF9FF5213E19A7AF2B4DF0A25ED0BB46668571F898873C98D28F
TrID 50.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
10.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
10.5% (.EXE) Win64 Executable (generic) (6522/11/2)
8.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
7.2% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon b2a89c96a2cada72 (2'283 x Formbook, 981 x Loki, 803 x AgentTesla)
Reporter Alex_sev
Tags:electron exe infostealer vidar

Intelligence


File Origin
# of uploads :
1
# of downloads :
224
Origin country :
IR IR
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Searching for the window
Сreating synchronization primitives
Creating a process from a recently created file
Creating a window
Running batch commands
Creating a process with a hidden window
Creating a file
Searching for synchronization primitives
Launching the process to interact with network services
Launching a process
Creating a file in the %AppData% subdirectories
Moving a file to the %AppData% subdirectory
DNS request
Connection attempt
Sending a custom TCP request
Forced system process termination
Deleting a recently created file
Using the Windows Management Instrumentation requests
Adding an exclusion to Microsoft Defender
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
adaptive-context anti-debug anti-vm base64 crypto crypto expand expired-cert fingerprint hacktool installer installer lolbin microsoft_visual_cc nsis obfuscated reconnaissance
Gathering data
Result
Malware family:
n/a
Score:
  10/10
Tags:
defense_evasion discovery execution trojan
Behaviour
Modifies registry class
Runs net.exe
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Executes a command shell one-liner
System Location Discovery: System Language Discovery
Hide Artifacts: Ignore Process Interrupts
Executes a VBScript file via the Windows Script Host.
Suspicious use of NtSetInformationThreadHideFromDebugger
Hide Artifacts: Hidden Window
Obfuscated Files or Information: Command Obfuscation
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Prevents Microsoft Defender from scanning certain paths by adding an exclusion.
System Binary Proxy Execution: Rundll32
Command and Scripting Interpreter: PowerShell
Downloads MZ/PE file
Windows security bypass
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments