MB-3cb1fce90249c12ef32dd836bb8ae2b6cabcb599551b1da402965c4c677417c2
high
📛 Threat Title
Vidar: 3cb1fce90249c12ef32dd836bb8ae2b6cabcb599551b1da402965c4c677417c2.bin
Description
File type: exe. Size: 6547888 bytes. Tags: exe, signed, Vidar. Reporter: anonymous. First seen: 2026-09-25 11:28:35.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_imphash
4f2f006e2ecf7172ad368f8289dc96c1
IOC database
- Type
- hash_imphash
- Value
4f2f006e2ecf7172ad368f8289dc96c1- First seen
- Last seen
- Attached to this threat
- Appears in
- 61 threats
- Description
- imphash of URLhaus payload 774041365d4bc2b1…
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
3cb1fce90249c12ef32dd836bb8ae2b6cabcb599551b1da402965c4c677417c2
VT 34 / 75
IOC database
- Type
- hash_sha256
- Value
3cb1fce90249c12ef32dd836bb8ae2b6cabcb599551b1da402965c4c677417c2- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Vidar
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 34 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | Trojan:Multi/Wacatac.B9nj |
| Avast | malicious | Win64:Evo-gen [Trj] |
| AVG | malicious | Win64:Evo-gen [Trj] |
| Avira | malicious | TR/W64.Evo |
| Bkav | malicious | W32.Malware.22408884 |
| CrowdStrike | malicious | win/malicious_confidence_70% (W) |
| CTX | malicious | exe.trojan.generic |
| Cylance | malicious | Unsafe |
| Cynet | malicious | Malicious (score: 99) |
| DeepInstinct | malicious | MALICIOUS |
| DrWeb | malicious | Trojan.PWS.Steam.41640 |
| Elastic | malicious | malicious (high confidence) |
| ESET-NOD32 | malicious | WinGo/Kryptik.ABP trojan |
| F-Secure | malicious | Trojan.TR/W64.Evo |
| GData | malicious | Win32.Malware.KillAV.AOKIJR@gen |
| malicious | Detected |
|
| Gridinsoft | malicious | Trojan.Win64.Agent.cl |
| Ikarus | malicious | Trojan.W64.Evo |
| Kaspersky | malicious | Trojan.Win64.Agent.smhkzq |
| Kingsoft | malicious | Win64.Trojan.Agent.smhkzq |
| Malwarebytes | malicious | Spyware.Vidar |
| McAfeeD | malicious | ti!3CB1FCE90249 |
| Microsoft | malicious | Trojan:Win32/Egairtigado!rfn |
| Paloalto | malicious | generic.ml |
| Panda | malicious | Trj/PhxBzA.A |
| Rising | malicious | Trojan.Kryptik!8.8 (CLOUD) |
| Sangfor | malicious | Trojan.Win32.Kryptik.Vfpz |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | ML.Attribute.HighConfidence |
| TrellixENS | malicious | Artemis!15DBD0DB08AB |
| TrendMicro | malicious | TrojanSpy.Win64.VIDAR.YXGIYZ |
| TrendMicro-HouseCall | malicious | TrojanSpy.Win64.VIDAR.YXGIYZ |
| Varist | malicious | W64/WinGo.J4.gen!Eldorado |
| Webroot | malicious | Win.Trojan.Gen |
Details From VirusTotal
Basic Properties
| MD5 | 15dbd0db08ab33f23cb25ee04dc525fc |
| SHA-1 | 950502e8a540a26c74f60452b4dda4b75c94e4b0 |
| SHA-256 | 3cb1fce90249c12ef32dd836bb8ae2b6cabcb599551b1da402965c4c677417c2 |
| VHash | 066086656d15551d15545az2d!z |
| SSDEEP | 49152:kpujg/m9gsfUoVkdwZv8Z+dadvg8dtPa7d9J9NzoPQpyKlTbw17EuhnhjZTB5:dgu9gr+ag6Pa7/3N0cFWjh55 |
| TLSH | T191665B1359948265DA4AD375E1BF5203EAB5BC19D73532E3AE006D306F3A3D23AF6708 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32+ executable (GUI) x86-64, for MS Windows |
| File size | 6.2 MB |
History
| First seen on VirusTotal | 2026-09-25 06:53 UTC |
| Last submission | 2026-09-25 12:34 UTC |
| Last analysis | 2026-09-25 19:02 UTC |
| Last modified on VirusTotal | 2026-09-25 23:36 UTC |
Known Names
yiof9lqzi.exe59c731d47058eb72e79d80d7311d00bd.exe3wj3gqxrk.exe
hash_sha1
950502e8a540a26c74f60452b4dda4b75c94e4b0
VT 34 / 75
IOC database
- Type
- hash_sha1
- Value
950502e8a540a26c74f60452b4dda4b75c94e4b0- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 34 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | Trojan:Multi/Wacatac.B9nj |
| Avast | malicious | Win64:Evo-gen [Trj] |
| AVG | malicious | Win64:Evo-gen [Trj] |
| Avira | malicious | TR/W64.Evo |
| Bkav | malicious | W32.Malware.22408884 |
| CrowdStrike | malicious | win/malicious_confidence_70% (W) |
| CTX | malicious | exe.trojan.generic |
| Cylance | malicious | Unsafe |
| Cynet | malicious | Malicious (score: 99) |
| DeepInstinct | malicious | MALICIOUS |
| DrWeb | malicious | Trojan.PWS.Steam.41640 |
| Elastic | malicious | malicious (high confidence) |
| ESET-NOD32 | malicious | WinGo/Kryptik.ABP trojan |
| F-Secure | malicious | Trojan.TR/W64.Evo |
| GData | malicious | Win32.Malware.KillAV.AOKIJR@gen |
| malicious | Detected |
|
| Gridinsoft | malicious | Trojan.Win64.Agent.cl |
| Ikarus | malicious | Trojan.W64.Evo |
| Kaspersky | malicious | Trojan.Win64.Agent.smhkzq |
| Kingsoft | malicious | Win64.Trojan.Agent.smhkzq |
| Malwarebytes | malicious | Spyware.Vidar |
| McAfeeD | malicious | ti!3CB1FCE90249 |
| Microsoft | malicious | Trojan:Win32/Egairtigado!rfn |
| Paloalto | malicious | generic.ml |
| Panda | malicious | Trj/PhxBzA.A |
| Rising | malicious | Trojan.Kryptik!8.8 (CLOUD) |
| Sangfor | malicious | Trojan.Win32.Kryptik.Vfpz |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | ML.Attribute.HighConfidence |
| TrellixENS | malicious | Artemis!15DBD0DB08AB |
| TrendMicro | malicious | TrojanSpy.Win64.VIDAR.YXGIYZ |
| TrendMicro-HouseCall | malicious | TrojanSpy.Win64.VIDAR.YXGIYZ |
| Varist | malicious | W64/WinGo.J4.gen!Eldorado |
| Webroot | malicious | Win.Trojan.Gen |
Details From VirusTotal
Basic Properties
| MD5 | 15dbd0db08ab33f23cb25ee04dc525fc |
| SHA-1 | 950502e8a540a26c74f60452b4dda4b75c94e4b0 |
| SHA-256 | 3cb1fce90249c12ef32dd836bb8ae2b6cabcb599551b1da402965c4c677417c2 |
| VHash | 066086656d15551d15545az2d!z |
| SSDEEP | 49152:kpujg/m9gsfUoVkdwZv8Z+dadvg8dtPa7d9J9NzoPQpyKlTbw17EuhnhjZTB5:dgu9gr+ag6Pa7/3N0cFWjh55 |
| TLSH | T191665B1359948265DA4AD375E1BF5203EAB5BC19D73532E3AE006D306F3A3D23AF6708 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32+ executable (GUI) x86-64, for MS Windows |
| File size | 6.2 MB |
History
| First seen on VirusTotal | 2026-09-25 06:53 UTC |
| Last submission | 2026-09-25 12:34 UTC |
| Last analysis | 2026-09-25 19:02 UTC |
| Last modified on VirusTotal | 2026-09-25 23:36 UTC |
Known Names
yiof9lqzi.exe59c731d47058eb72e79d80d7311d00bd.exe3wj3gqxrk.exe
hash_md5
15dbd0db08ab33f23cb25ee04dc525fc
VT 34 / 75
IOC database
- Type
- hash_md5
- Value
15dbd0db08ab33f23cb25ee04dc525fc- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 34 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | Trojan:Multi/Wacatac.B9nj |
| Avast | malicious | Win64:Evo-gen [Trj] |
| AVG | malicious | Win64:Evo-gen [Trj] |
| Avira | malicious | TR/W64.Evo |
| Bkav | malicious | W32.Malware.22408884 |
| CrowdStrike | malicious | win/malicious_confidence_70% (W) |
| CTX | malicious | exe.trojan.generic |
| Cylance | malicious | Unsafe |
| Cynet | malicious | Malicious (score: 99) |
| DeepInstinct | malicious | MALICIOUS |
| DrWeb | malicious | Trojan.PWS.Steam.41640 |
| Elastic | malicious | malicious (high confidence) |
| ESET-NOD32 | malicious | WinGo/Kryptik.ABP trojan |
| F-Secure | malicious | Trojan.TR/W64.Evo |
| GData | malicious | Win32.Malware.KillAV.AOKIJR@gen |
| malicious | Detected |
|
| Gridinsoft | malicious | Trojan.Win64.Agent.cl |
| Ikarus | malicious | Trojan.W64.Evo |
| Kaspersky | malicious | Trojan.Win64.Agent.smhkzq |
| Kingsoft | malicious | Win64.Trojan.Agent.smhkzq |
| Malwarebytes | malicious | Spyware.Vidar |
| McAfeeD | malicious | ti!3CB1FCE90249 |
| Microsoft | malicious | Trojan:Win32/Egairtigado!rfn |
| Paloalto | malicious | generic.ml |
| Panda | malicious | Trj/PhxBzA.A |
| Rising | malicious | Trojan.Kryptik!8.8 (CLOUD) |
| Sangfor | malicious | Trojan.Win32.Kryptik.Vfpz |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | ML.Attribute.HighConfidence |
| TrellixENS | malicious | Artemis!15DBD0DB08AB |
| TrendMicro | malicious | TrojanSpy.Win64.VIDAR.YXGIYZ |
| TrendMicro-HouseCall | malicious | TrojanSpy.Win64.VIDAR.YXGIYZ |
| Varist | malicious | W64/WinGo.J4.gen!Eldorado |
| Webroot | malicious | Win.Trojan.Gen |
Details From VirusTotal
Basic Properties
| MD5 | 15dbd0db08ab33f23cb25ee04dc525fc |
| SHA-1 | 950502e8a540a26c74f60452b4dda4b75c94e4b0 |
| SHA-256 | 3cb1fce90249c12ef32dd836bb8ae2b6cabcb599551b1da402965c4c677417c2 |
| VHash | 066086656d15551d15545az2d!z |
| SSDEEP | 49152:kpujg/m9gsfUoVkdwZv8Z+dadvg8dtPa7d9J9NzoPQpyKlTbw17EuhnhjZTB5:dgu9gr+ag6Pa7/3N0cFWjh55 |
| TLSH | T191665B1359948265DA4AD375E1BF5203EAB5BC19D73532E3AE006D306F3A3D23AF6708 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32+ executable (GUI) x86-64, for MS Windows |
| File size | 6.2 MB |
History
| First seen on VirusTotal | 2026-09-25 06:53 UTC |
| Last submission | 2026-09-25 12:34 UTC |
| Last analysis | 2026-09-25 19:02 UTC |
| Last modified on VirusTotal | 2026-09-25 23:36 UTC |
Known Names
yiof9lqzi.exe59c731d47058eb72e79d80d7311d00bd.exe3wj3gqxrk.exe
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 6547888 bytes. Tags: exe, signed, Vidar. Reporter: anonymous. First seen: 2026-09-25 11:28:35.
Remediations (10)
-
web:any.run
Vidar is an information stealer trojan. It is either a fork of Vidar or the result of its evolution. Follow live malware statistics of this trojan and get new reports, samples, IOCs, etc.
-
web:eln0ty.github.io
Deep Analysis of Vidar Information Stealer 17 minute read On this page Vidar overview Sample Preparation (strings & dlls) Decrypt strings Building imports C2 Server How to understand the configuration format Folder generation Browsers 2 Factor Authentication software (2FA) Messengers Crypto Wallets Information log Result Other payloads Kill Task Exfiltration Conclusion Yara Rules Vidar (forked ...
-
web:hunt.io
Explore Vidar , a Windows-based info-stealing malware. Learn about its data theft capabilities, distribution methods, and mitigation strategies.
-
web:securityonline.info
A new Vidar stealer campaign uses the Factory-v3 loader and fake certificates to deploy malware. Learn how attackers hide XMRig and bypass security.
-
web:www.acronis.com
Vidar is an infostealer that harvests credentials to enable initial access brokers and ransomware crews. Read our complete guide to Vidar defense.
-
web:www.huntress.com
Vidar removal instructions Manual remediation can be risky, but professionals should start by isolating infected systems from the network. Use robust tools such as Huntress Endpoint Detection and Response (EDR) solutions or remediation tools to thoroughly clean the malware and restore affected systems safely.
-
web:www.malwarebytes.com
We found fake "verify you are human" pages on hacked WordPress sites that trick Windows users into installing the Vidar infostealer.
-
web:www.pcrisk.com
Vidar (also known as Vidar Stealer) is a trojan (a malicious program) commonly used by cyber criminals. The program steals various personal information from users who have computers infected with the virus.
-
web:www.vidarmotors.com
In the near future, they plan to fully integrate VIDAR into their plant's control system, allowing automatic speed adjustments based on demand. Once that's done, they will eliminate the control valve entirely, unlocking even greater operational efficiency, system reliability and lifespan, and cost and energy savings.
-
web:www.yazoul.net
Vidar threat intelligence: 1826 samples tracked, 51 daily reports, IOCs, detection rates, and C2 infrastructure. Updated daily from MalwareBazaar.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.