🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7e56189288270e5da9e00a7b52dbd6de7b4e24c83ca697ec8d0cbbf811f6dd61. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Vidar


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: 7e56189288270e5da9e00a7b52dbd6de7b4e24c83ca697ec8d0cbbf811f6dd61
SHA3-384 hash: b1846dffc3a1ae4abc7969c52ebb323e8b0039c516d081a2cc59bffc0013124b87f712328d9d3539ee0fdb06be99faa6
SHA1 hash: c2f55c37b14c108b1a87db227646eef6b88b03dc
MD5 hash: a5c8e32b382613113642b0a0c0c17726
humanhash: hot-river-east-network
File name:errtraff_inner_13476c6.bin
Download: download sample
Signature Vidar
File size:1'326'080 bytes
First seen:2026-09-24 19:55:24 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
ssdeep 12288:eGK5imhcJ+98GKwT0o4eFUSBcJRV88sZ0V60jj/odmzF7BdGsrwCa/XjNpbO:e5/hci8U+DHjj/oQF7ysECyr
TLSH T19255408FD49213B5F397FB73821AE6665DF6740680728634DF466D394F82E20A428ECD
TrID 51.9% (.EXE) Win64 Executable (generic) (6522/11/2)
16.1% (.EXE) OS/2 Executable (generic) (2029/13)
15.9% (.EXE) Generic Win/DOS Executable (2002/3)
15.9% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
Reporter MaciekGorzny
Tags:exe vidar

Intelligence


File Origin
# of uploads :
1
# of downloads :
13
Origin country :
PL PL
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
adaptive-context masquerade microsoft_visual_cc packed
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-09-24T18:24:00Z UTC
Last seen:
2026-09-25T17:42:00Z UTC
Hits:
~100
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout Win 64 Exe x64
Gathering data
Threat name:
Win64.Trojan.Vidar
Status:
Malicious
First seen:
2026-09-24 23:13:24 UTC
File Type:
PE+ (Exe)
AV detection:
23 of 38 (60.53%)
Threat level:
  5/5
Unpacked files
SH256 hash:
7e56189288270e5da9e00a7b52dbd6de7b4e24c83ca697ec8d0cbbf811f6dd61
MD5 hash:
a5c8e32b382613113642b0a0c0c17726
SHA1 hash:
c2f55c37b14c108b1a87db227646eef6b88b03dc
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:pe_no_import_table
Description:Detect pe file that no import table

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments