Threat Database Trojans Trojan.Vidar.RA

Trojan.Vidar.RA

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 25,341
Threat Level: 80 % (High)
Infected Computers: 23
First Seen: April 1, 2025
Last Seen: May 11, 2026
OS(es) Affected: Windows

The detection of Trojan.Vidar.RA on your system indicates a potential security threat that requires immediate attention. This type of malware can compromise your system's integrity and put your personal data at risk. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Trojan.Vidar.RA?

Trojan.Vidar.RA is a type of Trojan horse malware, which is a broad category of malicious software that disguises itself as legitimate programs. Trojans can be used to gain unauthorized access to a system, steal sensitive information, or disrupt system operation. The name Trojan.Vidar.RA suggests that it may be related to the Vidar malware family, but without further information, it's difficult to determine its exact characteristics or behavior.

How Trojan.Vidar.RA Operates

Once a system is infected with Trojan.Vidar.RA, the malware can operate in various ways, depending on its intended purpose. It may attempt to connect to a command and control server to receive instructions from its creators, or it may start scanning the system for sensitive information such as login credentials, financial data, or personal files. The malware may also try to exploit system vulnerabilities to gain elevated privileges or spread to other systems.

Trojan.Vidar.RA may use social engineering tactics, such as phishing or spear phishing, to trick users into installing the malware or providing sensitive information. It's also possible that the malware is spread through infected software downloads, compromised websites, or infected USB drives.

Symptoms of Infection

Systems infected with Trojan.Vidar.RA may exhibit various symptoms, including unusual system behavior, slow performance, or frequent crashes. Users may notice that their system is connecting to unknown servers or that their personal files are being accessed without their permission. In some cases, the malware may not display any noticeable symptoms, making it difficult to detect without the use of antivirus software.

  • Unexplained changes to system settings or configuration
  • Appearance of unknown programs or icons on the desktop
  • Unusual network activity or connections to unknown servers
  • Frequent system crashes or freezes

How to Remove Trojan.Vidar.RA

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for internet access.
  2. Use a reputable antivirus tool, such as SpyHunter, to perform a full scan of your system and detect any malware components.
  3. Uninstall any suspicious programs or applications that may be related to the malware.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another full scan to ensure that all malware components have been removed.

Conclusion

Removing Trojan.Vidar.RA from your system requires careful attention to detail and a thorough understanding of the malware's behavior. By following the steps outlined above and using reputable antivirus software, you can help protect your system and personal data from this type of threat. It's essential to remain vigilant and take proactive measures to prevent future infections, such as keeping your operating system and software up to date, using strong passwords, and avoiding suspicious downloads or email attachments.

Analysis Report

General information

Family Name: Trojan.Vidar.RA
Signature status: No Signature

Known Samples

MD5: fc9f1abe898ff6c2e2fe0ae095d25fab
SHA1: 91988904c0a92f524874ecc57649e8e5aea84ec1
SHA256: 64F0EC7E80A860C8673FB02843BC0AB4DB37C82A61BC72E16D6BF12C903AAD70
File Size: 2.00 MB, 2003968 bytes
MD5: fc2bb44be7bedef1c429b2fca887aea4
SHA1: 3c4467aab29ca787e9c74aa8fc210fe48c461748
SHA256: 7065976FC55546CC608C5D6B84AA383A7140E6C07BDB68B7BF9C1E5BEA0EECEA
File Size: 2.17 MB, 2171392 bytes
MD5: 1c101bd9e80fb38bcadff0fef8fc73fe
SHA1: 56693ece43da589b20b749590e4c334e46d6a8cf
SHA256: 09DED1FBDF170D0523D8F76F305F95177055B0EDE51432AB347FFE6C355D5DD6
File Size: 2.16 MB, 2161152 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have resources
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • 2+ executable sections
  • HighEntropy
  • No Version Info
  • x64

Block Information

Total Blocks: 1,391
Potentially Malicious Blocks: 420
Whitelisted Blocks: 971
Unknown Blocks: 0

Visual Map

x x x x 0 0 0 x 0 x x x x x 0 0 0 x x x x x 0 x 0 x x x 0 0 1 x x 0 x x 0 x 0 x 0 x 0 0 0 0 x x 0 x 0 0 0 x 0 0 x x x 0 x x 0 0 0 0 0 x x 0 x 0 x x 0 0 0 0 x 0 x x x x 0 x 0 x x 0 0 x 0 0 x x 0 x x 0 x x x x 0 x x 0 0 x 0 x 0 0 0 x 0 0 0 x 0 x 0 x 0 x x x x 0 0 x x 0 0 x 0 0 0 x x x 0 0 x 0 0 0 0 0 x 0 0 x 0 0 0 x x 0 0 0 x x 0 x x x x 0 0 0 0 0 0 0 x 0 0 x 0 x x 0 0 0 x x x 0 x x x x 0 0 0 0 x x 0 x x x 0 x 0 x 0 x x 0 0 0 0 0 x 0 0 0 0 0 x x 0 x x x 0 x x 0 x x x x 0 0 0 0 0 0 x 0 x 0 0 x x x 0 x 0 x 0 0 x 0 0 x 0 x 0 x 0 0 0 0 x x x x 0 x 0 0 0 x x 0 x 0 x x x 0 x 0 0 x x x 0 x x 0 x x x 0 x 0 0 x 0 0 x x 0 0 0 x 0 0 x 0 0 0 0 x 0 x 0 0 0 x 0 0 0 x 0 0 x x 0 0 0 0 0 x x x x x x 0 x 0 0 0 0 x x 0 0 x x 0 x x 0 x x x x x 0 0 0 x x x x x x 0 x 0 0 x 0 0 x x 0 x x x 0 x x x x 0 x 0 x x x x x 0 x 0 0 0 0 0 0 x x 0 0 x x 0 x x 0 x x x x x x 0 0 x x 0 x x 0 x 0 0 x x x x 0 x 0 0 x x x 0 x 0 0 x 0 0 0 x 0 0 x 0 x x x x 0 x x x 0 x 0 0 0 x x 0 0 x 0 x x 0 0 x 0 0 0 x x 0 x 0 0 x 0 x 0 0 x 0 0 x x x 0 0 x x x 0 0 x 0 0 x 0 0 x x x 0 0 0 0 x x 0 0 x x x x x 0 0 0 0 0 x x x x x 0 0 0 0 x x 0 0 x 0 0 x 0 x x x 0 0 0 0 0 x x x x 0 0 0 0 x x x 0 0 0 0 x x x x x 0 x 0 0 0 x x x x x x x 0 x 0 x 0 x 0 x x 0 0 x x x 0 x 0 x x x x x x x 0 x x x x x 0 x 0 x x 0 x x x x 0 x x x x x x x x x x 0 0 0 x 0 x x 0 0 0 x x x 0 x x x 0 0 x 0 x 0 x 0 x x x 0 x x 0 x x x 0 0 0 0 x x x x x 0 x 0 x x 0 0 x x 0 x 0 x x 0 x x 0 x x x x 0 0 x 0 x x 0 x x 0 x x x x 0 0 0 0 x 0 x x x x x x x x x x x x x 0 0 x 0 0 0 x x x 0 x x x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 2 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 x 0 x x x 0 0 x x 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Vidar.R
  • Vidar.RA

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
Show More
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Trending

Most Viewed

Loading...