Threat Database Trojans Trojan.Vidar.RA

Trojan.Vidar.RA

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Vidar.RA
Signature status: No Signature

Known Samples

MD5: fc9f1abe898ff6c2e2fe0ae095d25fab
SHA1: 91988904c0a92f524874ecc57649e8e5aea84ec1
SHA256: 64F0EC7E80A860C8673FB02843BC0AB4DB37C82A61BC72E16D6BF12C903AAD70
File Size: 2.00 MB, 2003968 bytes
MD5: fc2bb44be7bedef1c429b2fca887aea4
SHA1: 3c4467aab29ca787e9c74aa8fc210fe48c461748
SHA256: 7065976FC55546CC608C5D6B84AA383A7140E6C07BDB68B7BF9C1E5BEA0EECEA
File Size: 2.17 MB, 2171392 bytes
MD5: 1c101bd9e80fb38bcadff0fef8fc73fe
SHA1: 56693ece43da589b20b749590e4c334e46d6a8cf
SHA256: 09DED1FBDF170D0523D8F76F305F95177055B0EDE51432AB347FFE6C355D5DD6
File Size: 2.16 MB, 2161152 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have resources
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • 2+ executable sections
  • HighEntropy
  • No Version Info
  • x64

Block Information

Total Blocks: 1,391
Potentially Malicious Blocks: 420
Whitelisted Blocks: 971
Unknown Blocks: 0

Visual Map

x x x x 0 0 0 x 0 x x x x x 0 0 0 x x x x x 0 x 0 x x x 0 0 1 x x 0 x x 0 x 0 x 0 x 0 0 0 0 x x 0 x 0 0 0 x 0 0 x x x 0 x x 0 0 0 0 0 x x 0 x 0 x x 0 0 0 0 x 0 x x x x 0 x 0 x x 0 0 x 0 0 x x 0 x x 0 x x x x 0 x x 0 0 x 0 x 0 0 0 x 0 0 0 x 0 x 0 x 0 x x x x 0 0 x x 0 0 x 0 0 0 x x x 0 0 x 0 0 0 0 0 x 0 0 x 0 0 0 x x 0 0 0 x x 0 x x x x 0 0 0 0 0 0 0 x 0 0 x 0 x x 0 0 0 x x x 0 x x x x 0 0 0 0 x x 0 x x x 0 x 0 x 0 x x 0 0 0 0 0 x 0 0 0 0 0 x x 0 x x x 0 x x 0 x x x x 0 0 0 0 0 0 x 0 x 0 0 x x x 0 x 0 x 0 0 x 0 0 x 0 x 0 x 0 0 0 0 x x x x 0 x 0 0 0 x x 0 x 0 x x x 0 x 0 0 x x x 0 x x 0 x x x 0 x 0 0 x 0 0 x x 0 0 0 x 0 0 x 0 0 0 0 x 0 x 0 0 0 x 0 0 0 x 0 0 x x 0 0 0 0 0 x x x x x x 0 x 0 0 0 0 x x 0 0 x x 0 x x 0 x x x x x 0 0 0 x x x x x x 0 x 0 0 x 0 0 x x 0 x x x 0 x x x x 0 x 0 x x x x x 0 x 0 0 0 0 0 0 x x 0 0 x x 0 x x 0 x x x x x x 0 0 x x 0 x x 0 x 0 0 x x x x 0 x 0 0 x x x 0 x 0 0 x 0 0 0 x 0 0 x 0 x x x x 0 x x x 0 x 0 0 0 x x 0 0 x 0 x x 0 0 x 0 0 0 x x 0 x 0 0 x 0 x 0 0 x 0 0 x x x 0 0 x x x 0 0 x 0 0 x 0 0 x x x 0 0 0 0 x x 0 0 x x x x x 0 0 0 0 0 x x x x x 0 0 0 0 x x 0 0 x 0 0 x 0 x x x 0 0 0 0 0 x x x x 0 0 0 0 x x x 0 0 0 0 x x x x x 0 x 0 0 0 x x x x x x x 0 x 0 x 0 x 0 x x 0 0 x x x 0 x 0 x x x x x x x 0 x x x x x 0 x 0 x x 0 x x x x 0 x x x x x x x x x x 0 0 0 x 0 x x 0 0 0 x x x 0 x x x 0 0 x 0 x 0 x 0 x x x 0 x x 0 x x x 0 0 0 0 x x x x x 0 x 0 x x 0 0 x x 0 x 0 x x 0 x x 0 x x x x 0 0 x 0 x x 0 x x 0 x x x x 0 0 0 0 x 0 x x x x x x x x x x x x x 0 0 x 0 0 0 x x x 0 x x x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 2 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 x 0 x x x 0 0 x x 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Vidar.R
  • Vidar.RA

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
Show More
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Trending

Most Viewed

Loading...