s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-7d333afdb455aae365c9774f112b56a212c9386274482fd6d86edb83d8089015 high

📛 Threat Title

Vidar: 7d333afdb455aae365c9774f112b56a212c9386274482fd6d86edb83d8089015.bin

Category: Vidar Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 6745456 bytes. Tags: exe, signed, Vidar. Reporter: anonymous. First seen: 2026-09-25 09:20:20.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_imphash 4f2f006e2ecf7172ad368f8289dc96c1

IOC database

Type
hash_imphash
Value
4f2f006e2ecf7172ad368f8289dc96c1
First seen
Last seen
Attached to this threat
Appears in
61 threats
Description
imphash of URLhaus payload 774041365d4bc2b1…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 7d333afdb455aae365c9774f112b56a212c9386274482fd6d86edb83d8089015 VT 38 / 75

IOC database

Type
hash_sha256
Value
7d333afdb455aae365c9774f112b56a212c9386274482fd6d86edb83d8089015
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Vidar

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 38 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Trojan/Win.Generic.R613610
alibabacloud malicious Trojan:Win/Agent.steunn
Avast malicious Win64:Evo-gen [Trj]
AVG malicious Win64:Evo-gen [Trj]
Avira malicious TR/W64.Evo
BitDefender malicious Trojan.GenericKD.81564736
Bkav malicious W32.Malware.A32F263B
CrowdStrike malicious win/malicious_confidence_100% (W)
CTX malicious exe.trojan.generic
Cynet malicious Malicious (score: 99)
DeepInstinct malicious MALICIOUS
DrWeb malicious Trojan.PWS.Steam.41638
Elastic malicious malicious (high confidence)
Emsisoft malicious Trojan.GenericKD.81564736 (B)
ESET-NOD32 malicious WinGo/Kryptik.ABT trojan
F-Secure malicious Trojan.TR/W64.Evo
Fortinet malicious W64/Vidar.AAR!tr
GData malicious Win32.Malware.KillAV.OCBOM8@gen
Google malicious Detected
Gridinsoft malicious Trojan.Win64.Agent.cl
Ikarus malicious Trojan.W64.Evo
Kaspersky malicious Trojan.Win64.Agent.smhksx
Kingsoft malicious Win64.Trojan.Agent.smhksx
Lionic malicious Trojan.Win32.Agent.Y!c
MaxSecure malicious Trojan.Malware.121218.susgen
McAfeeD malicious ti!7D333AFDB455
Microsoft malicious Trojan:Win32/Egairtigado!rfn
MicroWorld-eScan malicious Trojan.GenericKD.81564736
Paloalto malicious generic.ml
Panda malicious Trj/PhxBzA.A
Sangfor malicious Trojan.Win64.Evo.Vo8f
Sophos malicious Mal/Generic-S
Symantec malicious ML.Attribute.HighConfidence
Tencent malicious Win32.Trojan.FalseSign.Aujl
TrellixENS malicious Artemis!0917D04D7089
TrendMicro malicious TrojanSpy.Win64.VIDAR.YXGIYZ
TrendMicro-HouseCall malicious TrojanSpy.Win64.VIDAR.YXGIYZ
Varist malicious W64/WinGo.I.gen!Eldorado

Details From VirusTotal

Basic Properties
MD50917d04d70893445cff870e227409855
SHA-16cbef41e936ed2507942e3da8977835268a94087
SHA-2567d333afdb455aae365c9774f112b56a212c9386274482fd6d86edb83d8089015
VHash066086657d15551d15545az2d!z
SSDEEP49152:4a8+bNcCfCXuY7GlvcRkIUNx1gsz/VJvU6sauokdrElvjoh50kavura8hhwE:lPfCFKlvUkIUmub1s52G3ZN5CE
TLSHT1AC665B0F6591221AED579774B3A26A25AB78FC06C33032E36EC02BB45F377C569B4B14
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32+ executable (GUI) x86-64, for MS Windows
File size6.4 MB
History
First seen on VirusTotal2026-09-25 02:07 UTC
Last submission2026-09-25 10:39 UTC
Last analysis2026-09-25 19:02 UTC
Last modified on VirusTotal2026-09-25 21:03 UTC
Known Names
  • yudg9.exe
  • 312f08d40808565882f15ede459965e0.exe
  • i447eyr.exe
hash_sha1 6cbef41e936ed2507942e3da8977835268a94087 VT 38 / 75

IOC database

Type
hash_sha1
Value
6cbef41e936ed2507942e3da8977835268a94087
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 38 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Trojan/Win.Generic.R613610
alibabacloud malicious Trojan:Win/Agent.steunn
Avast malicious Win64:Evo-gen [Trj]
AVG malicious Win64:Evo-gen [Trj]
Avira malicious TR/W64.Evo
BitDefender malicious Trojan.GenericKD.81564736
Bkav malicious W32.Malware.A32F263B
CrowdStrike malicious win/malicious_confidence_100% (W)
CTX malicious exe.trojan.generic
Cynet malicious Malicious (score: 99)
DeepInstinct malicious MALICIOUS
DrWeb malicious Trojan.PWS.Steam.41638
Elastic malicious malicious (high confidence)
Emsisoft malicious Trojan.GenericKD.81564736 (B)
ESET-NOD32 malicious WinGo/Kryptik.ABT trojan
F-Secure malicious Trojan.TR/W64.Evo
Fortinet malicious W64/Vidar.AAR!tr
GData malicious Win32.Malware.KillAV.OCBOM8@gen
Google malicious Detected
Gridinsoft malicious Trojan.Win64.Agent.cl
Ikarus malicious Trojan.W64.Evo
Kaspersky malicious Trojan.Win64.Agent.smhksx
Kingsoft malicious Win64.Trojan.Agent.smhksx
Lionic malicious Trojan.Win32.Agent.Y!c
MaxSecure malicious Trojan.Malware.121218.susgen
McAfeeD malicious ti!7D333AFDB455
Microsoft malicious Trojan:Win32/Egairtigado!rfn
MicroWorld-eScan malicious Trojan.GenericKD.81564736
Paloalto malicious generic.ml
Panda malicious Trj/PhxBzA.A
Sangfor malicious Trojan.Win64.Evo.Vo8f
Sophos malicious Mal/Generic-S
Symantec malicious ML.Attribute.HighConfidence
Tencent malicious Win32.Trojan.FalseSign.Aujl
TrellixENS malicious Artemis!0917D04D7089
TrendMicro malicious TrojanSpy.Win64.VIDAR.YXGIYZ
TrendMicro-HouseCall malicious TrojanSpy.Win64.VIDAR.YXGIYZ
Varist malicious W64/WinGo.I.gen!Eldorado

Details From VirusTotal

Basic Properties
MD50917d04d70893445cff870e227409855
SHA-16cbef41e936ed2507942e3da8977835268a94087
SHA-2567d333afdb455aae365c9774f112b56a212c9386274482fd6d86edb83d8089015
VHash066086657d15551d15545az2d!z
SSDEEP49152:4a8+bNcCfCXuY7GlvcRkIUNx1gsz/VJvU6sauokdrElvjoh50kavura8hhwE:lPfCFKlvUkIUmub1s52G3ZN5CE
TLSHT1AC665B0F6591221AED579774B3A26A25AB78FC06C33032E36EC02BB45F377C569B4B14
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32+ executable (GUI) x86-64, for MS Windows
File size6.4 MB
History
First seen on VirusTotal2026-09-25 02:07 UTC
Last submission2026-09-25 10:39 UTC
Last analysis2026-09-25 19:02 UTC
Last modified on VirusTotal2026-09-25 21:03 UTC
Known Names
  • yudg9.exe
  • 312f08d40808565882f15ede459965e0.exe
  • i447eyr.exe
hash_md5 0917d04d70893445cff870e227409855 VT 38 / 75

IOC database

Type
hash_md5
Value
0917d04d70893445cff870e227409855
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 38 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Trojan/Win.Generic.R613610
alibabacloud malicious Trojan:Win/Agent.steunn
Avast malicious Win64:Evo-gen [Trj]
AVG malicious Win64:Evo-gen [Trj]
Avira malicious TR/W64.Evo
BitDefender malicious Trojan.GenericKD.81564736
Bkav malicious W32.Malware.A32F263B
CrowdStrike malicious win/malicious_confidence_100% (W)
CTX malicious exe.trojan.generic
Cynet malicious Malicious (score: 99)
DeepInstinct malicious MALICIOUS
DrWeb malicious Trojan.PWS.Steam.41638
Elastic malicious malicious (high confidence)
Emsisoft malicious Trojan.GenericKD.81564736 (B)
ESET-NOD32 malicious WinGo/Kryptik.ABT trojan
F-Secure malicious Trojan.TR/W64.Evo
Fortinet malicious W64/Vidar.AAR!tr
GData malicious Win32.Malware.KillAV.OCBOM8@gen
Google malicious Detected
Gridinsoft malicious Trojan.Win64.Agent.cl
Ikarus malicious Trojan.W64.Evo
Kaspersky malicious Trojan.Win64.Agent.smhksx
Kingsoft malicious Win64.Trojan.Agent.smhksx
Lionic malicious Trojan.Win32.Agent.Y!c
MaxSecure malicious Trojan.Malware.121218.susgen
McAfeeD malicious ti!7D333AFDB455
Microsoft malicious Trojan:Win32/Egairtigado!rfn
MicroWorld-eScan malicious Trojan.GenericKD.81564736
Paloalto malicious generic.ml
Panda malicious Trj/PhxBzA.A
Sangfor malicious Trojan.Win64.Evo.Vo8f
Sophos malicious Mal/Generic-S
Symantec malicious ML.Attribute.HighConfidence
Tencent malicious Win32.Trojan.FalseSign.Aujl
TrellixENS malicious Artemis!0917D04D7089
TrendMicro malicious TrojanSpy.Win64.VIDAR.YXGIYZ
TrendMicro-HouseCall malicious TrojanSpy.Win64.VIDAR.YXGIYZ
Varist malicious W64/WinGo.I.gen!Eldorado

Details From VirusTotal

Basic Properties
MD50917d04d70893445cff870e227409855
SHA-16cbef41e936ed2507942e3da8977835268a94087
SHA-2567d333afdb455aae365c9774f112b56a212c9386274482fd6d86edb83d8089015
VHash066086657d15551d15545az2d!z
SSDEEP49152:4a8+bNcCfCXuY7GlvcRkIUNx1gsz/VJvU6sauokdrElvjoh50kavura8hhwE:lPfCFKlvUkIUmub1s52G3ZN5CE
TLSHT1AC665B0F6591221AED579774B3A26A25AB78FC06C33032E36EC02BB45F377C569B4B14
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32+ executable (GUI) x86-64, for MS Windows
File size6.4 MB
History
First seen on VirusTotal2026-09-25 02:07 UTC
Last submission2026-09-25 10:39 UTC
Last analysis2026-09-25 19:02 UTC
Last modified on VirusTotal2026-09-25 21:03 UTC
Known Names
  • yudg9.exe
  • 312f08d40808565882f15ede459965e0.exe
  • i447eyr.exe

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 6745456 bytes. Tags: exe, signed, Vidar. Reporter: anonymous. First seen: 2026-09-25 09:20:20.

Remediations (10)

  • web:any.run

    Vidar is an information stealer trojan. It is either a fork of Vidar or the result of its evolution. Follow live malware statistics of this trojan and get new reports, samples, IOCs, etc.

  • web:blackpointcyber.com

    Vidar Stealer is often deployed via social engineering attacks - phishing emails with malicious attachments and links - and drive-by downloads. Vidar Stealer has also been observed using malicious Google ads to spread the malware variant. Vidar Stealer has been observed impersonating legitimate software such as Advanced IP Scanner, Adobe Photoshop, Microsoft Teams, and Adobe Illustrator.

  • web:cybersecuritynews.com

    Vidar stealer evolves its code to evade detection while stealing passwords, cookies, wallet data, and system details from victims.

  • web:eln0ty.github.io

    Deep Analysis of Vidar Information Stealer 17 minute read On this page Vidar overview Sample Preparation (strings & dlls) Decrypt strings Building imports C2 Server How to understand the configuration format Folder generation Browsers 2 Factor Authentication software (2FA) Messengers Crypto Wallets Information log Result Other payloads Kill Task Exfiltration Conclusion Yara Rules Vidar (forked ...

  • web:hunt.io

    Explore Vidar , a Windows-based info-stealing malware. Learn about its data theft capabilities, distribution methods, and mitigation strategies.

  • web:www.acronis.com

    Vidar is an infostealer that harvests credentials to enable initial access brokers and ransomware crews. Read our complete guide to Vidar defense.

  • web:www.huntress.com

    Vidar removal instructions Manual remediation can be risky, but professionals should start by isolating infected systems from the network. Use robust tools such as Huntress Endpoint Detection and Response (EDR) solutions or remediation tools to thoroughly clean the malware and restore affected systems safely.

  • web:www.malwarebytes.com

    We found fake "verify you are human" pages on hacked WordPress sites that trick Windows users into installing the Vidar infostealer.

  • web:www.pcrisk.com

    Vidar (also known as Vidar Stealer) is a trojan (a malicious program) commonly used by cyber criminals. The program steals various personal information from users who have computers infected with the virus.

  • web:www.yazoul.net

    Vidar threat intelligence: 1826 samples tracked, 51 daily reports, IOCs, detection rates, and C2 infrastructure. Updated daily from MalwareBazaar.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.