MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fe4a641b424d5b9a394f5da71f1043d13c46a5cbbf03f6f9f13b28a56685c5bd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Vidar


Vendor detections: 11


Intelligence 11 IOCs YARA 34 File information Comments

SHA256 hash: fe4a641b424d5b9a394f5da71f1043d13c46a5cbbf03f6f9f13b28a56685c5bd
SHA3-384 hash: 312a661f412414e972dc0a3f92009f5be40745d6d0f4296d2e24b5d5bf91a46c48d39fd7a5f9d22073ccc9476652b24f
SHA1 hash: a3aa8149d3bd2fe3f02c9aa24776cc9aa4440d2f
MD5 hash: 1c67f96a74b81a3e5008b2980822497d
humanhash: angel-bakerloo-oregon-tennis
File name:21Installer.exe
Download: download sample
Signature Vidar
File size:48'772'608 bytes
First seen:2024-11-23 12:15:21 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash ff9f3a86709796c17211f9df12aae74d (4 x LummaStealer, 4 x Vidar, 2 x CobaltStrike)
ssdeep 393216:VzwHHHU1I9x8tR4gOkXVUsFpSH7SUi7Id7D:Vzwp78z5V5g7T
TLSH T16DB76B60F9EBC5F1E6030571849B512F67307D049B28CADBEA00BE6DE473BA16DB3625
gimphash 1eafc41c46953cba644169eda9e361d281d9ee59ab2ac8251aa41ac2cc39d56f
TrID 40.3% (.EXE) Win64 Executable (generic) (10522/11/4)
19.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
17.2% (.EXE) Win32 Executable (generic) (4504/4/1)
7.7% (.EXE) OS/2 Executable (generic) (2029/13)
7.6% (.EXE) Generic Win/DOS Executable (2002/3)
Magika pebin
File icon (PE):PE icon
dhash icon f8f0f4c8c8c8d8f0 (8'803 x RedLineStealer, 5'108 x Amadey, 288 x Smoke Loader)
Reporter aachum
Tags:exe vidar


Avatar
iamaachum
https://www.youtube.com/channel/UCMAqMvHaDiC8bGiMvyNPzAQ/community?lb=Ugkx95zXudiOe2kumAoABBgtReejeAohUlhI => https://github.com/PiNodeNetwork/Nodeservices/releases/download/TradeLab/21Installer.zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
271
Origin country :
ES ES
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
21Installer.zip
Verdict:
Malicious activity
Analysis date:
2024-11-23 11:29:21 UTC
Tags:
arch-exec nodejs crypto-regex golang discordgrabber generic stealer

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
90.2%
Tags:
crypt shell lien sage
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
golang packed packed packer_detected
Result
Threat name:
Stealc, Vidar
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
AI detected suspicious sample
Allocates memory in foreign processes
Attempt to bypass Chrome Application-Bound Encryption
C2 URLs / IPs found in malware configuration
Contains functionality to inject code into remote processes
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Injects a PE file into a foreign processes
Monitors registry run keys for changes
Searches for specific processes (likely to inject)
Suricata IDS alerts for network traffic
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal Bitcoin Wallet information
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to steal Crypto Currency Wallets
Writes to foreign memory regions
Yara detected AntiVM3
Yara detected Powershell download and execute
Yara detected Stealc
Yara detected Vidar
Yara detected Vidar stealer
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1561443 Sample: 21Installer.exe Startdate: 23/11/2024 Architecture: WINDOWS Score: 100 40 exp0ns.sbs 2->40 42 t.me 2->42 64 Suricata IDS alerts for network traffic 2->64 66 Found malware configuration 2->66 68 Yara detected Stealc 2->68 70 7 other signatures 2->70 9 21Installer.exe 1 2->9         started        12 msedge.exe 8 2->12         started        signatures3 process4 signatures5 74 Writes to foreign memory regions 9->74 76 Allocates memory in foreign processes 9->76 78 Injects a PE file into a foreign processes 9->78 14 BitLockerToGo.exe 141 9->14         started        19 msedge.exe 12->19         started        process6 dnsIp7 50 exp0ns.sbs 49.13.32.95, 443, 49826, 49832 HETZNER-ASDE Germany 14->50 52 t.me 149.154.167.99, 443, 49820 TELEGRAMRU United Kingdom 14->52 54 127.0.0.1 unknown unknown 14->54 32 C:\ProgramData\vcruntime140.dll, PE32 14->32 dropped 34 C:\ProgramData\softokn3.dll, PE32 14->34 dropped 36 C:\ProgramData\nss3.dll, PE32 14->36 dropped 38 3 other files (none is malicious) 14->38 dropped 56 Attempt to bypass Chrome Application-Bound Encryption 14->56 58 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 14->58 60 Found many strings related to Crypto-Wallets (likely being stolen) 14->60 62 7 other signatures 14->62 21 msedge.exe 2 11 14->21         started        24 chrome.exe 8 14->24         started        file8 signatures9 process10 dnsIp11 72 Monitors registry run keys for changes 21->72 27 msedge.exe 21->27         started        44 192.168.2.10, 138, 443, 49264 unknown unknown 24->44 46 239.255.255.250 unknown Reserved 24->46 29 chrome.exe 24->29         started        signatures12 process13 dnsIp14 48 www.google.com 142.250.181.68, 443, 49890, 49894 GOOGLEUS United States 29->48
Gathering data
Threat name:
Win32.Trojan.Generic
Status:
Malicious
First seen:
2024-11-23 12:16:20 UTC
File Type:
PE (Exe)
Extracted files:
39
AV detection:
13 of 24 (54.17%)
Threat level:
  2/5
Verdict:
malicious
Label(s):
Similar samples:
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Suspicious use of AdjustPrivilegeToken
System Location Discovery: System Language Discovery
Verdict:
Suspicious
Tags:
n/a
YARA:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202408_html_TelegramBot
Author:abuse.ch
Description:Detects potential JavaScript Telegram Bot inside HTML code
Rule name:ach_202409_html_FedEx_phish
Author:abuse.ch
Description:Detects potential HTML FedEx phishing forms
Rule name:Borland
Author:malware-lu
Rule name:command_and_control
Author:CD_R0M_
Description:This rule searches for common strings found by malware using C2. Based on a sample used by a Ransomware group
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__ConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:Detect_PowerShell_Obfuscation
Author:daniyyell
Description:Detects obfuscated PowerShell commands commonly used in malicious scripts.
Rule name:dsc
Author:Aaron DeVera
Description:Discord domains
Rule name:GoBinTest
Rule name:golang
Rule name:golang_binary_string
Description:Golang strings present
Rule name:HUN_APT29_EnvyScout_Jul_2023_1
Author:Arkbird_SOLG
Description:Hunting rule for detect possible Envyscout malware used by the APT29 group by patterns already used in the past
Rule name:identity_golang
Author:Eric Yocam
Description:find Golang malware
Rule name:malware_shellcode_hash
Author:JPCERT/CC Incident Response Group
Description:detect shellcode api hash value
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:reverse_http
Author:CD_R0M_
Description:Identify strings with http reversed (ptth)
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
Rule name:telegram_bot_api
Author:rectifyq
Description:Detects file containing Telegram Bot API
Rule name:test_Malaysia
Author:rectifyq
Description:Detects file containing malaysia string
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Vidar

Executable exe fe4a641b424d5b9a394f5da71f1043d13c46a5cbbf03f6f9f13b28a56685c5bd

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
Reviews
IDCapabilitiesEvidence
WIN32_PROCESS_APICan Create Process and Threadskernel32.dll::CloseHandle
kernel32.dll::CreateThread
WIN_BASE_APIUses Win Base APIkernel32.dll::LoadLibraryA
kernel32.dll::LoadLibraryW
kernel32.dll::GetSystemInfo
WIN_BASE_EXEC_APICan Execute other programskernel32.dll::WriteConsoleW
kernel32.dll::SetConsoleCtrlHandler
kernel32.dll::GetConsoleMode
WIN_BASE_IO_APICan Create Fileskernel32.dll::CreateFileA
kernel32.dll::GetSystemDirectoryA

Comments