Threat Database Trojans Trojan.Vidar.FB

Trojan.Vidar.FB

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Vidar.FB
Packers: UPX x64
Signature status: No Signature

Known Samples

MD5: e616f1c3d6c1833cb3781c03a0c2e094
SHA1: 2d99de4c5315e877b8c1b65e9c4ac72bdf16fa7b
SHA256: A059DC1F3EBB41582310F7C841A4C8F7442A5C0205C3C79E2C0EE559C8815509
File Size: 291.84 KB, 291840 bytes
MD5: f73fd79fbb5dabba09e133c13f6fa823
SHA1: 844108d1d962fa8cc938b1ef657e2aa15c84c515
SHA256: A4ABD142E6668050CC20B1D4DD095667DCCCCBC8C2674822AF682725A7441C20
File Size: 636.93 KB, 636928 bytes
MD5: 247048abd55317eea4125fd005603ec5
SHA1: 265481319d7cb5fd47fcd98161fba6340838d389
SHA256: FA245A155A129614E23B9DC92334FB78E2FF7896DD649CF490304DEE0D2565A5
File Size: 645.12 KB, 645120 bytes
MD5: db2e9d33e74538bfcdb40a8f790ba977
SHA1: 82a8b40e89107ce11f3297588516328bc3e37184
SHA256: D56EB6E52852E83C57930CFFE5CF812522ECB3FC24F137D29634783B6A47CF95
File Size: 278.53 KB, 278528 bytes
MD5: af1285c0f9d5fe640a6dd65e5b4ad30d
SHA1: 1fbeb8211519325e58355fe0420e1946ebcdf748
SHA256: 106FFEC87882F140FB281377D91EAB714C0322C4D44792185FC66B5680703CA7
File Size: 278.53 KB, 278528 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • CryptUnprotectData
  • HighEntropy
  • No CryptProtectData
  • No Version Info
  • packed
  • VirtualQueryEx
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 135
Potentially Malicious Blocks: 10
Whitelisted Blocks: 2
Unknown Blocks: 123

Visual Map

? x ? ? ? ? ? ? ? ? ? ? ? 0 0 ? x x ? ? ? ? ? x ? ? ? ? ? ? x x x ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Vidar.FB

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Trending

Most Viewed

Loading...