🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 aa943c02f06f0fa004355fb82a9e2a06342e5a77e3383125dcf2abfef7f04c31. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Vidar


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: aa943c02f06f0fa004355fb82a9e2a06342e5a77e3383125dcf2abfef7f04c31
SHA3-384 hash: 543dc7d0439aeb765cdcb0b8f7498204e1411ef04292bad28ed40c18fb561efa75fa96a703867f2748553c8979a38d72
SHA1 hash: 59d35aa1eddd77da3d1bd6550edf10afdd85cf31
MD5 hash: 6f84592e00ee3c67e662992f02dd3683
humanhash: december-foxtrot-wisconsin-alabama
File name:MDE_File_Sample_f9eeec54d199f3929309c113730286eb4cbf1527.zip
Download: download sample
Signature Vidar
File size:4'148'909 bytes
First seen:2026-02-17 15:31:26 UTC
Last seen:Never
File type: zip
MIME type:application/zip
Note:This file is a password protected archive. The password is: infected
ssdeep 98304:uMoS+5T7WzrMmdJbKacCQCNNY4Zw5JVVarEADM82+:uMxOWzrMiRR1N3w5JVVaJop+
TLSH T11616338CF1CB7B6211BBA72D53047494211F496C97FA2F6CB5E94DA842CCE8C4A9CCB5
Magika zip
Reporter GoBoom
Tags:bat vidar zip


Avatar
GoBoom
Dropped by powershell script from russian ip.
It's unknown how the script was started.

Intelligence


File Origin
# of uploads :
1
# of downloads :
83
Origin country :
CH CH
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:w34snw53.bat
File size:26'579'784 bytes
SHA256 hash: d48d239fd7fb7f4f9ad3fb2e8b1ef1b6ec62ff3bd05ae0e163f7112edec7be13
MD5 hash: 299774854db41ba228332e01d0cacdbb
MIME type:text/plain
Signature Vidar
Vendor Threat Intelligence
Verdict:
Malicious
Score:
81.4%
Tags:
shell spawn sage
Gathering data
Gathering data
Threat name:
Binary.Trojan.Generic
Status:
Suspicious
First seen:
2026-02-17 15:33:40 UTC
File Type:
Binary (Archive)
AV detection:
3 of 24 (12.50%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:donutloader family:vidar loader stealer
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Contacts third-party web service commonly abused for C2
Looks up external IP address via web service
Checks computer location settings
Deletes itself
Detects DonutLoader
Detects Vidar Stealer
DonutLoader
Donutloader family
Vidar
Vidar family
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments