Threat Database Trojans Trojan.Vidar.Gen.G

Trojan.Vidar.Gen.G

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Vidar.Gen.G
Signature status: No Signature

Known Samples

MD5: c85fec39496b41e5f61aa724dfdc12d5
SHA1: b85a24f7298fd7d0df336f92d2404798b1c3c970
SHA256: 5B005FBEB63D8BC0FD3090898AAFC87D33F4B4032F9A9379E2B519307616E8C5
File Size: 927.23 KB, 927232 bytes
MD5: 761a74eb147a67af959c3e10b636e1c0
SHA1: 162f22b03ca097f2eba2e25048c42847d26dc8fb
SHA256: FDBC68123616530CABB8D74863EA570A2A2C40B37CBC754E12B213B67E11A70C
File Size: 588.80 KB, 588800 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • No Version Info
  • VirtualQueryEx
  • x64

Block Information

Total Blocks: 354
Potentially Malicious Blocks: 346
Whitelisted Blocks: 8
Unknown Blocks: 0

Visual Map

x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x 0 x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Trending

Most Viewed

Loading...