🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 affbb003f93d939eada88497d6bdd4e335fa32e5d8cfacb1486acbc2cce1b1c5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Vidar


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: affbb003f93d939eada88497d6bdd4e335fa32e5d8cfacb1486acbc2cce1b1c5
SHA3-384 hash: f2e9ba87bd3f8d5ba9bd33efb4189d72f1f8a419528e66dbc545fdda73ec8e275dcc873532dace006cb704a855d9d3c6
SHA1 hash: f19e3b7c60b73261dbe2a99b78c53b15cc26e0c2
MD5 hash: 47e30dc6fc9a22c718a748e686341e0d
humanhash: cup-florida-batman-king
File name:affbb003f93d939eada88497d6bdd4e335fa32e5d8cfacb1486acbc2cce1b1c5.bin
Download: download sample
Signature Vidar
File size:95'895'464 bytes
First seen:2026-09-03 01:36:49 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash d42595b695fc008ef2c56aabd8efd68e (1'268 x Vidar, 328 x RemusStealer, 134 x Stealc)
ssdeep 1572864:ygcl8g5ab6KuYbMHnWAz3hZWiJUSuYRVBhrcq6RTJq5AgkYYmnrNe366n3nwbRv9:cBu6SoHWAxEiJ9R9t6RlhgBJg366n3nU
TLSH T1BA2833476C916469D9229B38E47B4261BF647CCCCB3673A32D50B2302F247C1AEFAB55
TrID 27.0% (.EXE) Win64 Executable (generic) (6522/11/2)
20.8% (.EXE) Win16 NE executable (generic) (5038/12/1)
18.6% (.EXE) Win32 Executable (generic) (4504/4/1)
8.5% (.ICL) Windows Icons Library (generic) (2059/9)
8.4% (.EXE) OS/2 Executable (generic) (2029/13)
Magika pebin
Reporter Anonymous
Tags:exe vidar

Intelligence


File Origin
# of uploads :
1
# of downloads :
178
Origin country :
CH CH
Vendor Threat Intelligence
Gathering data
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
No threats detected
Analysis date:
2026-09-03 02:09:53 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Сreating synchronization primitives
Connection attempt
Sending a custom TCP request
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm base64 bloated crypto golang masquerade overlay
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-09-02T18:53:00Z UTC
Last seen:
2026-09-02T21:18:00Z UTC
Hits:
~100
Gathering data
Threat name:
Win64.Packed.Generic
Status:
Suspicious
First seen:
2026-09-03 01:40:59 UTC
File Type:
PE+ (Exe)
AV detection:
7 of 36 (19.44%)
Threat level:
  1/5
Result
Malware family:
Score:
  10/10
Tags:
family:vidar botnet:4e497d09d1dc0c0a364ee7b2b6897d80 stealer
Behaviour
Suspicious behavior: EnumeratesProcesses
Family: Vidar
Malware Config
C2 Extraction:
https://62.238.126.31
https://telegram.me/nag0e
https://community.fandom.com/wikia.php?controller=UserProfile&method=getUserData&format=json&userId=63727183
https://dev.epicgames.com/community/api/user_profiles/profile.json?hash_id=XmE5L
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments