Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | Feb. 6, 2025, 9:57 a.m. | Feb. 6, 2025, 10:01 a.m. |
-
jrirkfiweid.exe "C:\Users\test22\AppData\Local\Temp\jrirkfiweid.exe"
1932
Name | Response | Post-Analysis Lookup |
---|---|---|
t.me | 149.154.167.99 | |
steamcommunity.com | 104.75.33.105 |
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.103:49207 104.75.33.105:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 Extended Validation Server CA | unknown=US, unknown=Washington, unknown=Private Organization, serialNumber=602 290 773, C=US, ST=Washington, L=Bellevue, O=Valve Corp, CN=store.steampowered.com | 83:75:0b:54:d5:9e:34:40:6f:c2:2c:fc:be:5f:db:00:04:0d:d6:83 |
TLSv1 192.168.56.103:49166 104.75.33.105:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 Extended Validation Server CA | unknown=US, unknown=Washington, unknown=Private Organization, serialNumber=602 290 773, C=US, ST=Washington, L=Bellevue, O=Valve Corp, CN=store.steampowered.com | 83:75:0b:54:d5:9e:34:40:6f:c2:2c:fc:be:5f:db:00:04:0d:d6:83 |
TLSv1 192.168.56.103:49175 104.75.33.105:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 Extended Validation Server CA | unknown=US, unknown=Washington, unknown=Private Organization, serialNumber=602 290 773, C=US, ST=Washington, L=Bellevue, O=Valve Corp, CN=store.steampowered.com | 83:75:0b:54:d5:9e:34:40:6f:c2:2c:fc:be:5f:db:00:04:0d:d6:83 |
TLSv1 192.168.56.103:49198 104.75.33.105:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 Extended Validation Server CA | unknown=US, unknown=Washington, unknown=Private Organization, serialNumber=602 290 773, C=US, ST=Washington, L=Bellevue, O=Valve Corp, CN=store.steampowered.com | 83:75:0b:54:d5:9e:34:40:6f:c2:2c:fc:be:5f:db:00:04:0d:d6:83 |
TLSv1 192.168.56.103:49184 104.75.33.105:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 Extended Validation Server CA | unknown=US, unknown=Washington, unknown=Private Organization, serialNumber=602 290 773, C=US, ST=Washington, L=Bellevue, O=Valve Corp, CN=store.steampowered.com | 83:75:0b:54:d5:9e:34:40:6f:c2:2c:fc:be:5f:db:00:04:0d:d6:83 |
TLSv1 192.168.56.103:49269 104.75.33.105:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 Extended Validation Server CA | unknown=US, unknown=Washington, unknown=Private Organization, serialNumber=602 290 773, C=US, ST=Washington, L=Bellevue, O=Valve Corp, CN=store.steampowered.com | 83:75:0b:54:d5:9e:34:40:6f:c2:2c:fc:be:5f:db:00:04:0d:d6:83 |
TLSv1 192.168.56.103:49238 104.75.33.105:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 Extended Validation Server CA | unknown=US, unknown=Washington, unknown=Private Organization, serialNumber=602 290 773, C=US, ST=Washington, L=Bellevue, O=Valve Corp, CN=store.steampowered.com | 83:75:0b:54:d5:9e:34:40:6f:c2:2c:fc:be:5f:db:00:04:0d:d6:83 |
TLSv1 192.168.56.103:49278 104.75.33.105:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 Extended Validation Server CA | unknown=US, unknown=Washington, unknown=Private Organization, serialNumber=602 290 773, C=US, ST=Washington, L=Bellevue, O=Valve Corp, CN=store.steampowered.com | 83:75:0b:54:d5:9e:34:40:6f:c2:2c:fc:be:5f:db:00:04:0d:d6:83 |
TLSv1 192.168.56.103:49216 104.75.33.105:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 Extended Validation Server CA | unknown=US, unknown=Washington, unknown=Private Organization, serialNumber=602 290 773, C=US, ST=Washington, L=Bellevue, O=Valve Corp, CN=store.steampowered.com | 83:75:0b:54:d5:9e:34:40:6f:c2:2c:fc:be:5f:db:00:04:0d:d6:83 |
TLSv1 192.168.56.103:49229 104.75.33.105:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 Extended Validation Server CA | unknown=US, unknown=Washington, unknown=Private Organization, serialNumber=602 290 773, C=US, ST=Washington, L=Bellevue, O=Valve Corp, CN=store.steampowered.com | 83:75:0b:54:d5:9e:34:40:6f:c2:2c:fc:be:5f:db:00:04:0d:d6:83 |
TLSv1 192.168.56.103:49247 104.75.33.105:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 Extended Validation Server CA | unknown=US, unknown=Washington, unknown=Private Organization, serialNumber=602 290 773, C=US, ST=Washington, L=Bellevue, O=Valve Corp, CN=store.steampowered.com | 83:75:0b:54:d5:9e:34:40:6f:c2:2c:fc:be:5f:db:00:04:0d:d6:83 |
TLSv1 192.168.56.103:49260 104.75.33.105:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 Extended Validation Server CA | unknown=US, unknown=Washington, unknown=Private Organization, serialNumber=602 290 773, C=US, ST=Washington, L=Bellevue, O=Valve Corp, CN=store.steampowered.com | 83:75:0b:54:d5:9e:34:40:6f:c2:2c:fc:be:5f:db:00:04:0d:d6:83 |
pdb_path | C:\Users\Administrator\Desktop\vdr1\Release\vdr1.pdb |
section | .00cfg |
suspicious_features | GET method with no useragent header | suspicious_request | GET https://steamcommunity.com/profiles/76561199824159981 |
request | GET https://steamcommunity.com/profiles/76561199824159981 |
host | 95.217.25.45 |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\F81F111D0E5AB58D396F7BF525577FD30FDC95AA\Blob |
process | jrirkfiweid.exe | useragent | |||||||
process | jrirkfiweid.exe | useragent | Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:136.0) Gecko/20100101 Firefox/136.0 |
Bkav | W32.AIDetectMalware |
Lionic | Trojan.Win32.Vidar.i!c |
Cynet | Malicious (score: 100) |
CAT-QuickHeal | Trojan.Ghanarava.1738787732d55bc3 |
Skyhigh | BehavesLike.Win32.Generic.ch |
ALYac | Gen:Variant.Doina.84985 |
Cylance | Unsafe |
VIPRE | Gen:Variant.Doina.84985 |
CrowdStrike | win/malicious_confidence_100% (W) |
BitDefender | Gen:Variant.Lazy.649375 |
K7GW | Trojan ( 005a977a1 ) |
K7AntiVirus | Trojan ( 005a977a1 ) |
Arcabit | Trojan.Doina.D14BF9 |
VirIT | Trojan.Win32.GenusT.EOMV |
Symantec | ML.Attribute.HighConfidence |
Elastic | malicious (high confidence) |
ESET-NOD32 | a variant of Win32/Vidar.A |
APEX | Malicious |
Avast | Win32:PWSX-gen [Trj] |
ClamAV | Win.Packed.Mikey-10032681-0 |
Kaspersky | Trojan-PSW.Win32.Stealerc.pvq |
Alibaba | TrojanPSW:Win32/Stealerc.85b699b5 |
MicroWorld-eScan | Gen:Variant.Lazy.649375 |
Rising | Stealer.Vidar!1.11757 (CLASSIC) |
Emsisoft | Gen:Variant.Lazy.649375 (B) |
F-Secure | Trojan.TR/Redcap.wfunp |
DrWeb | Trojan.PWS.Vidar.69 |
McAfeeD | Real Protect-LS!2049C2A57CF7 |
Trapmine | suspicious.low.ml.score |
CTX | exe.trojan.vidar |
Sophos | Mal/Generic-S |
SentinelOne | Static AI - Suspicious PE |
FireEye | Generic.mg.2049c2a57cf70a27 |
Detected | |
Avira | TR/Redcap.wfunp |
Antiy-AVL | Trojan/Win32.Sabsik |
Kingsoft | malware.kb.a.987 |
Gridinsoft | Ransom.Win32.Sabsik.sa |
GData | Gen:Variant.Lazy.649375 |
Varist | W32/ABTrojan.MZAJ-3400 |
AhnLab-V3 | Trojan/Win.Generic.C5726392 |
McAfee | Artemis!2049C2A57CF7 |
DeepInstinct | MALICIOUS |
VBA32 | BScope.TrojanPSW.Vidar |
Malwarebytes | Spyware.Vidar |
Ikarus | Trojan.Win32.Vidar |
Tencent | Trojan-Banker.Win32.Bandra.16000514 |
huorong | TrojanSpy/Stealer.ou |
MaxSecure | Trojan.Malware.327652896.susgen |
Fortinet | W32/Vidar.A!tr |