s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-1971187ab4d213be8a295cef2223002122dd6d6692fa906f2697b6cc11458a1f high

📛 Threat Title

Vidar: 1971187ab4d213be8a295cef2223002122dd6d6692fa906f2697b6cc11458a1f.exe

Category: Vidar Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 6624176 bytes. Tags: exe, signed, stealer, vidar. Reporter: Kejult. First seen: 2026-09-25 11:18:49.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_imphash 4f2f006e2ecf7172ad368f8289dc96c1

IOC database

Type
hash_imphash
Value
4f2f006e2ecf7172ad368f8289dc96c1
First seen
Last seen
Attached to this threat
Appears in
61 threats
Description
imphash of URLhaus payload 774041365d4bc2b1…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 1971187ab4d213be8a295cef2223002122dd6d6692fa906f2697b6cc11458a1f VT 35 / 75

IOC database

Type
hash_sha256
Value
1971187ab4d213be8a295cef2223002122dd6d6692fa906f2697b6cc11458a1f
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Vidar

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 35 of 75 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious Trojan[stealer]:Multi/Wacatac.B9nj
Antiy-AVL malicious Trojan[PSW]/Win32.StealerC
Avast malicious Win64:Evo-gen [Trj]
AVG malicious Win64:Evo-gen [Trj]
Avira malicious TR/W64.Evo
Bkav malicious W32.Malware.D3AF98DC
CrowdStrike malicious win/malicious_confidence_100% (W)
CTX malicious exe.trojan.generic
Cylance malicious Unsafe
Cynet malicious Malicious (score: 99)
DeepInstinct malicious MALICIOUS
DrWeb malicious Trojan.PWS.Steam.41642
Elastic malicious malicious (high confidence)
ESET-NOD32 malicious WinGo/Kryptik.ABP trojan
F-Secure malicious Trojan.TR/W64.Evo
Fortinet malicious W32/Kryptik.ABP!tr
GData malicious Win32.Malware.KillAV.CJZ57I@gen
Google malicious Detected
Ikarus malicious Trojan.W64.Evo
Kaspersky malicious Trojan.Win64.Agent.smhlap
Kingsoft malicious Win64.Trojan.Agent.smhlap
Lionic malicious Trojan.Win32.Agent.Y!c
Malwarebytes malicious Spyware.Vidar
McAfeeD malicious ti!1971187AB4D2
Microsoft malicious Trojan:Win32/Egairtigado!rfn
Paloalto malicious generic.ml
Rising malicious Stealer.Stealerc!8.17BE0 (CLOUD)
Sangfor malicious Trojan.Win64.Agent.Vdni
Sophos malicious Mal/Generic-S
Symantec malicious ML.Attribute.HighConfidence
TrellixENS malicious Artemis!2BC9E607EA27
TrendMicro malicious TrojanSpy.Win64.VIDAR.YXGIYZ
TrendMicro-HouseCall malicious TrojanSpy.Win64.VIDAR.YXGIYZ
Varist malicious W64/ABApplication.RLHI-5542
Webroot malicious Win.Trojan.Gen

Details From VirusTotal

Basic Properties
MD52bc9e607ea27d9dbdc38286546ed40f2
SHA-1c64d60cd5b3ad2ed854c00f9da0833f9a476316d
SHA-2561971187ab4d213be8a295cef2223002122dd6d6692fa906f2697b6cc11458a1f
VHash066086656d15551d15545az2d!z
SSDEEP49152:uHsQ6ayAg7VenFHwcRAL4c1Q9DKn8uVfIEI3w5b9njeFHKudWZ55WMiaiVpzvpIx:4/PvIQw5b9njeFqlAhzxIJuy
TLSHT15E665B17649042A4DA4AD375E1BF5203EAB5BC19DB3572D3AE006E706F3A3D23AF5B04
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32+ executable (GUI) x86-64, for MS Windows
File size6.3 MB
History
First seen on VirusTotal2026-09-25 09:10 UTC
Last submission2026-09-26 01:16 UTC
Last analysis2026-09-26 01:16 UTC
Last modified on VirusTotal2026-09-26 01:22 UTC
Known Names
  • Setup.exe
  • ew8a5n.exe
  • 1971187ab4d213be8a295cef2223002122dd6d6692fa906f2697b6cc11458a1f.exe
hash_sha1 c64d60cd5b3ad2ed854c00f9da0833f9a476316d VT 35 / 75

IOC database

Type
hash_sha1
Value
c64d60cd5b3ad2ed854c00f9da0833f9a476316d
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 35 of 75 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious Trojan[stealer]:Multi/Wacatac.B9nj
Antiy-AVL malicious Trojan[PSW]/Win32.StealerC
Avast malicious Win64:Evo-gen [Trj]
AVG malicious Win64:Evo-gen [Trj]
Avira malicious TR/W64.Evo
Bkav malicious W32.Malware.D3AF98DC
CrowdStrike malicious win/malicious_confidence_100% (W)
CTX malicious exe.trojan.generic
Cylance malicious Unsafe
Cynet malicious Malicious (score: 99)
DeepInstinct malicious MALICIOUS
DrWeb malicious Trojan.PWS.Steam.41642
Elastic malicious malicious (high confidence)
ESET-NOD32 malicious WinGo/Kryptik.ABP trojan
F-Secure malicious Trojan.TR/W64.Evo
Fortinet malicious W32/Kryptik.ABP!tr
GData malicious Win32.Malware.KillAV.CJZ57I@gen
Google malicious Detected
Ikarus malicious Trojan.W64.Evo
Kaspersky malicious Trojan.Win64.Agent.smhlap
Kingsoft malicious Win64.Trojan.Agent.smhlap
Lionic malicious Trojan.Win32.Agent.Y!c
Malwarebytes malicious Spyware.Vidar
McAfeeD malicious ti!1971187AB4D2
Microsoft malicious Trojan:Win32/Egairtigado!rfn
Paloalto malicious generic.ml
Rising malicious Stealer.Stealerc!8.17BE0 (CLOUD)
Sangfor malicious Trojan.Win64.Agent.Vdni
Sophos malicious Mal/Generic-S
Symantec malicious ML.Attribute.HighConfidence
TrellixENS malicious Artemis!2BC9E607EA27
TrendMicro malicious TrojanSpy.Win64.VIDAR.YXGIYZ
TrendMicro-HouseCall malicious TrojanSpy.Win64.VIDAR.YXGIYZ
Varist malicious W64/ABApplication.RLHI-5542
Webroot malicious Win.Trojan.Gen

Details From VirusTotal

Basic Properties
MD52bc9e607ea27d9dbdc38286546ed40f2
SHA-1c64d60cd5b3ad2ed854c00f9da0833f9a476316d
SHA-2561971187ab4d213be8a295cef2223002122dd6d6692fa906f2697b6cc11458a1f
VHash066086656d15551d15545az2d!z
SSDEEP49152:uHsQ6ayAg7VenFHwcRAL4c1Q9DKn8uVfIEI3w5b9njeFHKudWZ55WMiaiVpzvpIx:4/PvIQw5b9njeFqlAhzxIJuy
TLSHT15E665B17649042A4DA4AD375E1BF5203EAB5BC19DB3572D3AE006E706F3A3D23AF5B04
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32+ executable (GUI) x86-64, for MS Windows
File size6.3 MB
History
First seen on VirusTotal2026-09-25 09:10 UTC
Last submission2026-09-26 01:16 UTC
Last analysis2026-09-26 01:16 UTC
Last modified on VirusTotal2026-09-26 01:22 UTC
Known Names
  • Setup.exe
  • ew8a5n.exe
  • 1971187ab4d213be8a295cef2223002122dd6d6692fa906f2697b6cc11458a1f.exe
hash_md5 2bc9e607ea27d9dbdc38286546ed40f2 VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/2bc9e607ea27d9dbdc38286546ed40f2

IOC database

Type
hash_md5
Value
2bc9e607ea27d9dbdc38286546ed40f2
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/2bc9e607ea27d9dbdc38286546ed40f2

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 6624176 bytes. Tags: exe, signed, stealer, vidar. Reporter: Kejult. First seen: 2026-09-25 11:18:49.

Remediations (10)

  • web:any.run

    Vidar is an information stealer trojan. It is either a fork of Vidar or the result of its evolution. Follow live malware statistics of this trojan and get new reports, samples, IOCs, etc.

  • web:any.run

    Online sandbox report for vidar .exe, tagged as trojan, stealer, vidar , loader, verdict: Malicious activity

  • web:cybersecuritynews.com

    Vidar stealer evolves its code to evade detection while stealing passwords, cookies, wallet data, and system details from victims.

  • web:eln0ty.github.io

    Deep Analysis of Vidar Information Stealer 17 minute read On this page Vidar overview Sample Preparation (strings & dlls) Decrypt strings Building imports C2 Server How to understand the configuration format Folder generation Browsers 2 Factor Authentication software (2FA) Messengers Crypto Wallets Information log Result Other payloads Kill Task Exfiltration Conclusion Yara Rules Vidar (forked ...

  • web:github.com

    This analysis covers an in-depth reverse engineering of Vidar Stealer 2.0, a sophisticated information stealer that uses advanced evasion techniques to remain undetected. Key findings include: Task Scheduler Tampering: Modifies system task timestamps to 1999 to evade forensic analysis. Explorer.exe Process Hollowing: Injects shellcode into the legitimate Windows Explorer process. Microsoft ...

  • web:hunt.io

    Explore Vidar , a Windows-based info-stealing malware. Learn about its data theft capabilities, distribution methods, and mitigation strategies.

  • web:www.acronis.com

    Vidar is an infostealer that harvests credentials to enable initial access brokers and ransomware crews. Read our complete guide to Vidar defense.

  • web:www.huntress.com

    Vidar removal instructions Manual remediation can be risky, but professionals should start by isolating infected systems from the network. Use robust tools such as Huntress Endpoint Detection and Response (EDR) solutions or remediation tools to thoroughly clean the malware and restore affected systems safely.

  • web:www.malwarebytes.com

    We found fake "verify you are human" pages on hacked WordPress sites that trick Windows users into installing the Vidar infostealer.

  • web:www.pcrisk.com

    Once executed, the commands download a script from a remote server, injecting the Vidar malware (or Stealc). Instant automatic malware removal: Manual threat removal might be a lengthy and complicated process that requires advanced IT skills. Combo Cleaner is a professional automatic malware removal tool that is recommended to get rid of malware.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.