MB-7d333afdb455aae365c9774f112b56a212c9386274482fd6d86edb83d8089015
high
📛 Threat Title
Vidar: 7d333afdb455aae365c9774f112b56a212c9386274482fd6d86edb83d8089015.bin
Description
File type: exe. Size: 6745456 bytes. Tags: exe, signed, Vidar. Reporter: anonymous. First seen: 2026-09-25 09:20:20.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_imphash
4f2f006e2ecf7172ad368f8289dc96c1
IOC database
- Type
- hash_imphash
- Value
4f2f006e2ecf7172ad368f8289dc96c1- First seen
- Last seen
- Attached to this threat
- Appears in
- 61 threats
- Description
- imphash of URLhaus payload 774041365d4bc2b1…
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
7d333afdb455aae365c9774f112b56a212c9386274482fd6d86edb83d8089015
VT 38 / 75
IOC database
- Type
- hash_sha256
- Value
7d333afdb455aae365c9774f112b56a212c9386274482fd6d86edb83d8089015- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Vidar
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 38 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Trojan/Win.Generic.R613610 |
| alibabacloud | malicious | Trojan:Win/Agent.steunn |
| Avast | malicious | Win64:Evo-gen [Trj] |
| AVG | malicious | Win64:Evo-gen [Trj] |
| Avira | malicious | TR/W64.Evo |
| BitDefender | malicious | Trojan.GenericKD.81564736 |
| Bkav | malicious | W32.Malware.A32F263B |
| CrowdStrike | malicious | win/malicious_confidence_100% (W) |
| CTX | malicious | exe.trojan.generic |
| Cynet | malicious | Malicious (score: 99) |
| DeepInstinct | malicious | MALICIOUS |
| DrWeb | malicious | Trojan.PWS.Steam.41638 |
| Elastic | malicious | malicious (high confidence) |
| Emsisoft | malicious | Trojan.GenericKD.81564736 (B) |
| ESET-NOD32 | malicious | WinGo/Kryptik.ABT trojan |
| F-Secure | malicious | Trojan.TR/W64.Evo |
| Fortinet | malicious | W64/Vidar.AAR!tr |
| GData | malicious | Win32.Malware.KillAV.OCBOM8@gen |
| malicious | Detected |
|
| Gridinsoft | malicious | Trojan.Win64.Agent.cl |
| Ikarus | malicious | Trojan.W64.Evo |
| Kaspersky | malicious | Trojan.Win64.Agent.smhksx |
| Kingsoft | malicious | Win64.Trojan.Agent.smhksx |
| Lionic | malicious | Trojan.Win32.Agent.Y!c |
| MaxSecure | malicious | Trojan.Malware.121218.susgen |
| McAfeeD | malicious | ti!7D333AFDB455 |
| Microsoft | malicious | Trojan:Win32/Egairtigado!rfn |
| MicroWorld-eScan | malicious | Trojan.GenericKD.81564736 |
| Paloalto | malicious | generic.ml |
| Panda | malicious | Trj/PhxBzA.A |
| Sangfor | malicious | Trojan.Win64.Evo.Vo8f |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | ML.Attribute.HighConfidence |
| Tencent | malicious | Win32.Trojan.FalseSign.Aujl |
| TrellixENS | malicious | Artemis!0917D04D7089 |
| TrendMicro | malicious | TrojanSpy.Win64.VIDAR.YXGIYZ |
| TrendMicro-HouseCall | malicious | TrojanSpy.Win64.VIDAR.YXGIYZ |
| Varist | malicious | W64/WinGo.I.gen!Eldorado |
Details From VirusTotal
Basic Properties
| MD5 | 0917d04d70893445cff870e227409855 |
| SHA-1 | 6cbef41e936ed2507942e3da8977835268a94087 |
| SHA-256 | 7d333afdb455aae365c9774f112b56a212c9386274482fd6d86edb83d8089015 |
| VHash | 066086657d15551d15545az2d!z |
| SSDEEP | 49152:4a8+bNcCfCXuY7GlvcRkIUNx1gsz/VJvU6sauokdrElvjoh50kavura8hhwE:lPfCFKlvUkIUmub1s52G3ZN5CE |
| TLSH | T1AC665B0F6591221AED579774B3A26A25AB78FC06C33032E36EC02BB45F377C569B4B14 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32+ executable (GUI) x86-64, for MS Windows |
| File size | 6.4 MB |
History
| First seen on VirusTotal | 2026-09-25 02:07 UTC |
| Last submission | 2026-09-25 10:39 UTC |
| Last analysis | 2026-09-25 19:02 UTC |
| Last modified on VirusTotal | 2026-09-25 21:03 UTC |
Known Names
yudg9.exe312f08d40808565882f15ede459965e0.exei447eyr.exe
hash_sha1
6cbef41e936ed2507942e3da8977835268a94087
VT 38 / 75
IOC database
- Type
- hash_sha1
- Value
6cbef41e936ed2507942e3da8977835268a94087- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 38 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Trojan/Win.Generic.R613610 |
| alibabacloud | malicious | Trojan:Win/Agent.steunn |
| Avast | malicious | Win64:Evo-gen [Trj] |
| AVG | malicious | Win64:Evo-gen [Trj] |
| Avira | malicious | TR/W64.Evo |
| BitDefender | malicious | Trojan.GenericKD.81564736 |
| Bkav | malicious | W32.Malware.A32F263B |
| CrowdStrike | malicious | win/malicious_confidence_100% (W) |
| CTX | malicious | exe.trojan.generic |
| Cynet | malicious | Malicious (score: 99) |
| DeepInstinct | malicious | MALICIOUS |
| DrWeb | malicious | Trojan.PWS.Steam.41638 |
| Elastic | malicious | malicious (high confidence) |
| Emsisoft | malicious | Trojan.GenericKD.81564736 (B) |
| ESET-NOD32 | malicious | WinGo/Kryptik.ABT trojan |
| F-Secure | malicious | Trojan.TR/W64.Evo |
| Fortinet | malicious | W64/Vidar.AAR!tr |
| GData | malicious | Win32.Malware.KillAV.OCBOM8@gen |
| malicious | Detected |
|
| Gridinsoft | malicious | Trojan.Win64.Agent.cl |
| Ikarus | malicious | Trojan.W64.Evo |
| Kaspersky | malicious | Trojan.Win64.Agent.smhksx |
| Kingsoft | malicious | Win64.Trojan.Agent.smhksx |
| Lionic | malicious | Trojan.Win32.Agent.Y!c |
| MaxSecure | malicious | Trojan.Malware.121218.susgen |
| McAfeeD | malicious | ti!7D333AFDB455 |
| Microsoft | malicious | Trojan:Win32/Egairtigado!rfn |
| MicroWorld-eScan | malicious | Trojan.GenericKD.81564736 |
| Paloalto | malicious | generic.ml |
| Panda | malicious | Trj/PhxBzA.A |
| Sangfor | malicious | Trojan.Win64.Evo.Vo8f |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | ML.Attribute.HighConfidence |
| Tencent | malicious | Win32.Trojan.FalseSign.Aujl |
| TrellixENS | malicious | Artemis!0917D04D7089 |
| TrendMicro | malicious | TrojanSpy.Win64.VIDAR.YXGIYZ |
| TrendMicro-HouseCall | malicious | TrojanSpy.Win64.VIDAR.YXGIYZ |
| Varist | malicious | W64/WinGo.I.gen!Eldorado |
Details From VirusTotal
Basic Properties
| MD5 | 0917d04d70893445cff870e227409855 |
| SHA-1 | 6cbef41e936ed2507942e3da8977835268a94087 |
| SHA-256 | 7d333afdb455aae365c9774f112b56a212c9386274482fd6d86edb83d8089015 |
| VHash | 066086657d15551d15545az2d!z |
| SSDEEP | 49152:4a8+bNcCfCXuY7GlvcRkIUNx1gsz/VJvU6sauokdrElvjoh50kavura8hhwE:lPfCFKlvUkIUmub1s52G3ZN5CE |
| TLSH | T1AC665B0F6591221AED579774B3A26A25AB78FC06C33032E36EC02BB45F377C569B4B14 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32+ executable (GUI) x86-64, for MS Windows |
| File size | 6.4 MB |
History
| First seen on VirusTotal | 2026-09-25 02:07 UTC |
| Last submission | 2026-09-25 10:39 UTC |
| Last analysis | 2026-09-25 19:02 UTC |
| Last modified on VirusTotal | 2026-09-25 21:03 UTC |
Known Names
yudg9.exe312f08d40808565882f15ede459965e0.exei447eyr.exe
hash_md5
0917d04d70893445cff870e227409855
VT 38 / 75
IOC database
- Type
- hash_md5
- Value
0917d04d70893445cff870e227409855- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 38 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Trojan/Win.Generic.R613610 |
| alibabacloud | malicious | Trojan:Win/Agent.steunn |
| Avast | malicious | Win64:Evo-gen [Trj] |
| AVG | malicious | Win64:Evo-gen [Trj] |
| Avira | malicious | TR/W64.Evo |
| BitDefender | malicious | Trojan.GenericKD.81564736 |
| Bkav | malicious | W32.Malware.A32F263B |
| CrowdStrike | malicious | win/malicious_confidence_100% (W) |
| CTX | malicious | exe.trojan.generic |
| Cynet | malicious | Malicious (score: 99) |
| DeepInstinct | malicious | MALICIOUS |
| DrWeb | malicious | Trojan.PWS.Steam.41638 |
| Elastic | malicious | malicious (high confidence) |
| Emsisoft | malicious | Trojan.GenericKD.81564736 (B) |
| ESET-NOD32 | malicious | WinGo/Kryptik.ABT trojan |
| F-Secure | malicious | Trojan.TR/W64.Evo |
| Fortinet | malicious | W64/Vidar.AAR!tr |
| GData | malicious | Win32.Malware.KillAV.OCBOM8@gen |
| malicious | Detected |
|
| Gridinsoft | malicious | Trojan.Win64.Agent.cl |
| Ikarus | malicious | Trojan.W64.Evo |
| Kaspersky | malicious | Trojan.Win64.Agent.smhksx |
| Kingsoft | malicious | Win64.Trojan.Agent.smhksx |
| Lionic | malicious | Trojan.Win32.Agent.Y!c |
| MaxSecure | malicious | Trojan.Malware.121218.susgen |
| McAfeeD | malicious | ti!7D333AFDB455 |
| Microsoft | malicious | Trojan:Win32/Egairtigado!rfn |
| MicroWorld-eScan | malicious | Trojan.GenericKD.81564736 |
| Paloalto | malicious | generic.ml |
| Panda | malicious | Trj/PhxBzA.A |
| Sangfor | malicious | Trojan.Win64.Evo.Vo8f |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | ML.Attribute.HighConfidence |
| Tencent | malicious | Win32.Trojan.FalseSign.Aujl |
| TrellixENS | malicious | Artemis!0917D04D7089 |
| TrendMicro | malicious | TrojanSpy.Win64.VIDAR.YXGIYZ |
| TrendMicro-HouseCall | malicious | TrojanSpy.Win64.VIDAR.YXGIYZ |
| Varist | malicious | W64/WinGo.I.gen!Eldorado |
Details From VirusTotal
Basic Properties
| MD5 | 0917d04d70893445cff870e227409855 |
| SHA-1 | 6cbef41e936ed2507942e3da8977835268a94087 |
| SHA-256 | 7d333afdb455aae365c9774f112b56a212c9386274482fd6d86edb83d8089015 |
| VHash | 066086657d15551d15545az2d!z |
| SSDEEP | 49152:4a8+bNcCfCXuY7GlvcRkIUNx1gsz/VJvU6sauokdrElvjoh50kavura8hhwE:lPfCFKlvUkIUmub1s52G3ZN5CE |
| TLSH | T1AC665B0F6591221AED579774B3A26A25AB78FC06C33032E36EC02BB45F377C569B4B14 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32+ executable (GUI) x86-64, for MS Windows |
| File size | 6.4 MB |
History
| First seen on VirusTotal | 2026-09-25 02:07 UTC |
| Last submission | 2026-09-25 10:39 UTC |
| Last analysis | 2026-09-25 19:02 UTC |
| Last modified on VirusTotal | 2026-09-25 21:03 UTC |
Known Names
yudg9.exe312f08d40808565882f15ede459965e0.exei447eyr.exe
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 6745456 bytes. Tags: exe, signed, Vidar. Reporter: anonymous. First seen: 2026-09-25 09:20:20.
Remediations (10)
-
web:any.run
Vidar is an information stealer trojan. It is either a fork of Vidar or the result of its evolution. Follow live malware statistics of this trojan and get new reports, samples, IOCs, etc.
-
web:blackpointcyber.com
Vidar Stealer is often deployed via social engineering attacks - phishing emails with malicious attachments and links - and drive-by downloads. Vidar Stealer has also been observed using malicious Google ads to spread the malware variant. Vidar Stealer has been observed impersonating legitimate software such as Advanced IP Scanner, Adobe Photoshop, Microsoft Teams, and Adobe Illustrator.
-
web:cybersecuritynews.com
Vidar stealer evolves its code to evade detection while stealing passwords, cookies, wallet data, and system details from victims.
-
web:eln0ty.github.io
Deep Analysis of Vidar Information Stealer 17 minute read On this page Vidar overview Sample Preparation (strings & dlls) Decrypt strings Building imports C2 Server How to understand the configuration format Folder generation Browsers 2 Factor Authentication software (2FA) Messengers Crypto Wallets Information log Result Other payloads Kill Task Exfiltration Conclusion Yara Rules Vidar (forked ...
-
web:hunt.io
Explore Vidar , a Windows-based info-stealing malware. Learn about its data theft capabilities, distribution methods, and mitigation strategies.
-
web:www.acronis.com
Vidar is an infostealer that harvests credentials to enable initial access brokers and ransomware crews. Read our complete guide to Vidar defense.
-
web:www.huntress.com
Vidar removal instructions Manual remediation can be risky, but professionals should start by isolating infected systems from the network. Use robust tools such as Huntress Endpoint Detection and Response (EDR) solutions or remediation tools to thoroughly clean the malware and restore affected systems safely.
-
web:www.malwarebytes.com
We found fake "verify you are human" pages on hacked WordPress sites that trick Windows users into installing the Vidar infostealer.
-
web:www.pcrisk.com
Vidar (also known as Vidar Stealer) is a trojan (a malicious program) commonly used by cyber criminals. The program steals various personal information from users who have computers infected with the virus.
-
web:www.yazoul.net
Vidar threat intelligence: 1826 samples tracked, 51 daily reports, IOCs, detection rates, and C2 infrastructure. Updated daily from MalwareBazaar.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.