MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 8a59a0e9b326966e4fb7353078bf82b765df754e575a3bfe3bb44220ffb41116. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Vidar
Vendor detections: 11
| SHA256 hash: | 8a59a0e9b326966e4fb7353078bf82b765df754e575a3bfe3bb44220ffb41116 |
|---|---|
| SHA3-384 hash: | 81bbea662d46b5df8d73bb0a856f97484a050b717541a3a99da1c65a5cb5fe5a3097e1b1e22610bafc05d61e6faa3fdf |
| SHA1 hash: | df0685de31373017c84f41bf4e0bd10dea2be2f7 |
| MD5 hash: | 120fb9ab24b1906d926f77bab1d0b535 |
| humanhash: | winter-avocado-floor-october |
| File name: | 120fb9ab24b1906d926f77bab1d0b535 |
| Download: | download sample |
| Signature | Vidar |
| File size: | 335'872 bytes |
| First seen: | 2023-11-28 09:20:48 UTC |
| Last seen: | 2023-11-28 10:59:51 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 534bfdca31fe91e5b425bdb4dcef0553 (3 x Vidar, 2 x Smoke Loader, 2 x Stealc) |
| ssdeep | 6144:b8mIrH6CaMcn6EAYv2SIjxm39LUG8uyx:AaCaMcnn2jI3C |
| TLSH | T194641A4382E53D54E9268B728F5FC6ECB70EF6528E5E7B665128DE1F04B21B2C1A3710 |
| TrID | 37.3% (.EXE) Win64 Executable (generic) (10523/12/4) 17.8% (.EXE) Win16 NE executable (generic) (5038/12/1) 15.9% (.EXE) Win32 Executable (generic) (4505/5/1) 7.3% (.ICL) Windows Icons Library (generic) (2059/9) 7.1% (.EXE) OS/2 Executable (generic) (2029/13) |
| File icon (PE): | |
| dhash icon | 0000204850702402 (1 x Vidar) |
| Reporter | |
| Tags: | 32 exe vidar |
Intelligence
File Origin
FRVendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
8a59a0e9b326966e4fb7353078bf82b765df754e575a3bfe3bb44220ffb41116
465bec204932baa110e7344f725d7a9acd5c1a599927e6a3a080aa31dc18101f
8c5858fdc6044de48a8f22b1ae51eb6bfa45befe91c3a854b2b0a99b79d41581
199c44e7bc7c65d6be9959d2d5875e9755104275de462698cd4f6ad94e57d25e
33b04a8d7bc2da4d5e00ce9acd0e5755daf961f1a8574ef84ba3d58761127d6a
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | DebuggerCheck__API |
|---|---|
| Reference: | https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara |
| Rule name: | SEH__vectored |
|---|---|
| Reference: | https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.url : hxxps://gons31cl.top/build.exe