Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | Feb. 21, 2025, 4:17 p.m. | Feb. 21, 2025, 4:20 p.m. |
Name | Response | Post-Analysis Lookup |
---|---|---|
t.me | 149.154.167.99 | |
steamcommunity.com | 23.49.154.73 |
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.103:49177 23.49.154.73:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 Extended Validation Server CA | unknown=US, unknown=Washington, unknown=Private Organization, serialNumber=602 290 773, C=US, ST=Washington, L=Bellevue, O=Valve Corp, CN=store.steampowered.com | 83:75:0b:54:d5:9e:34:40:6f:c2:2c:fc:be:5f:db:00:04:0d:d6:83 |
TLSv1 192.168.56.103:49209 23.49.154.73:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 Extended Validation Server CA | unknown=US, unknown=Washington, unknown=Private Organization, serialNumber=602 290 773, C=US, ST=Washington, L=Bellevue, O=Valve Corp, CN=store.steampowered.com | 83:75:0b:54:d5:9e:34:40:6f:c2:2c:fc:be:5f:db:00:04:0d:d6:83 |
TLSv1 192.168.56.103:49168 23.49.154.73:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 Extended Validation Server CA | unknown=US, unknown=Washington, unknown=Private Organization, serialNumber=602 290 773, C=US, ST=Washington, L=Bellevue, O=Valve Corp, CN=store.steampowered.com | 83:75:0b:54:d5:9e:34:40:6f:c2:2c:fc:be:5f:db:00:04:0d:d6:83 |
TLSv1 192.168.56.103:49186 23.49.154.73:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 Extended Validation Server CA | unknown=US, unknown=Washington, unknown=Private Organization, serialNumber=602 290 773, C=US, ST=Washington, L=Bellevue, O=Valve Corp, CN=store.steampowered.com | 83:75:0b:54:d5:9e:34:40:6f:c2:2c:fc:be:5f:db:00:04:0d:d6:83 |
TLSv1 192.168.56.103:49218 23.49.154.73:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 Extended Validation Server CA | unknown=US, unknown=Washington, unknown=Private Organization, serialNumber=602 290 773, C=US, ST=Washington, L=Bellevue, O=Valve Corp, CN=store.steampowered.com | 83:75:0b:54:d5:9e:34:40:6f:c2:2c:fc:be:5f:db:00:04:0d:d6:83 |
TLSv1 192.168.56.103:49200 23.49.154.73:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 Extended Validation Server CA | unknown=US, unknown=Washington, unknown=Private Organization, serialNumber=602 290 773, C=US, ST=Washington, L=Bellevue, O=Valve Corp, CN=store.steampowered.com | 83:75:0b:54:d5:9e:34:40:6f:c2:2c:fc:be:5f:db:00:04:0d:d6:83 |
TLSv1 192.168.56.103:49231 23.49.154.73:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 Extended Validation Server CA | unknown=US, unknown=Washington, unknown=Private Organization, serialNumber=602 290 773, C=US, ST=Washington, L=Bellevue, O=Valve Corp, CN=store.steampowered.com | 83:75:0b:54:d5:9e:34:40:6f:c2:2c:fc:be:5f:db:00:04:0d:d6:83 |
TLSv1 192.168.56.103:49240 23.49.154.73:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 Extended Validation Server CA | unknown=US, unknown=Washington, unknown=Private Organization, serialNumber=602 290 773, C=US, ST=Washington, L=Bellevue, O=Valve Corp, CN=store.steampowered.com | 83:75:0b:54:d5:9e:34:40:6f:c2:2c:fc:be:5f:db:00:04:0d:d6:83 |
TLSv1 192.168.56.103:49249 23.49.154.73:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 Extended Validation Server CA | unknown=US, unknown=Washington, unknown=Private Organization, serialNumber=602 290 773, C=US, ST=Washington, L=Bellevue, O=Valve Corp, CN=store.steampowered.com | 83:75:0b:54:d5:9e:34:40:6f:c2:2c:fc:be:5f:db:00:04:0d:d6:83 |
TLSv1 192.168.56.103:49271 23.49.154.73:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 Extended Validation Server CA | unknown=US, unknown=Washington, unknown=Private Organization, serialNumber=602 290 773, C=US, ST=Washington, L=Bellevue, O=Valve Corp, CN=store.steampowered.com | 83:75:0b:54:d5:9e:34:40:6f:c2:2c:fc:be:5f:db:00:04:0d:d6:83 |
TLSv1 192.168.56.103:49280 23.49.154.73:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 Extended Validation Server CA | unknown=US, unknown=Washington, unknown=Private Organization, serialNumber=602 290 773, C=US, ST=Washington, L=Bellevue, O=Valve Corp, CN=store.steampowered.com | 83:75:0b:54:d5:9e:34:40:6f:c2:2c:fc:be:5f:db:00:04:0d:d6:83 |
TLSv1 192.168.56.103:49262 23.49.154.73:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 Extended Validation Server CA | unknown=US, unknown=Washington, unknown=Private Organization, serialNumber=602 290 773, C=US, ST=Washington, L=Bellevue, O=Valve Corp, CN=store.steampowered.com | 83:75:0b:54:d5:9e:34:40:6f:c2:2c:fc:be:5f:db:00:04:0d:d6:83 |
section | .symtab |
suspicious_features | GET method with no useragent header | suspicious_request | GET https://steamcommunity.com/profiles/76561199828130190 |
request | GET https://steamcommunity.com/profiles/76561199828130190 |
url | http://localhost |
url | https://steamcommunity.com/profiles/76561199828130190 |
url | https://t.me/g02f04 |
description | Client_SW_User_Data_Stealer | rule | Client_SW_User_Data_Stealer | ||||||
description | ftp clients info stealer | rule | infoStealer_ftpClients_Zero | ||||||
description | Communications over RAW Socket | rule | Network_TCP_Socket | ||||||
description | Match Windows Http API call | rule | Str_Win32_Http_API | ||||||
description | Take ScreenShot | rule | ScreenShot | ||||||
description | PWS Memory | rule | Generic_PWS_Memory_Zero | ||||||
description | Communications over HTTP | rule | Network_HTTP | ||||||
description | Communications use DNS | rule | Network_DNS | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Anti-Sandbox checks for ThreatExpert | rule | antisb_threatExpert | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | Match Windows Inet API call | rule | Str_Win32_Internet_API | ||||||
description | Win32 PWS Loki | rule | Win32_PWS_Loki_m_Zero |
host | 95.217.24.123 |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\F81F111D0E5AB58D396F7BF525577FD30FDC95AA\Blob |
process | 1.exe | useragent | |||||||
process | 1.exe | useragent | Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) Chrome/131.0.0.0 Safari/537.36 OPR/116.0.0.0 |
Bkav | W32.AIDetectMalware |
Lionic | Trojan.Win32.Vidar.i!c |
Cynet | Malicious (score: 99) |
CAT-QuickHeal | cld.trojanpws.vidar |
Skyhigh | Artemis!Trojan |
Cylance | Unsafe |
CrowdStrike | win/malicious_confidence_100% (W) |
K7GW | Riskware ( 00584baa1 ) |
K7AntiVirus | Riskware ( 00584baa1 ) |
VirIT | Trojan.Win32.Genus.XOU |
Symantec | Trojan.Gen.MBT |
Elastic | malicious (moderate confidence) |
ESET-NOD32 | a variant of WinGo/Injector.EZ |
APEX | Malicious |
Avast | Win32:Malware-gen |
Kaspersky | Trojan-PSW.Win32.Vidar.ddq |
Alibaba | TrojanPSW:Win32/Vidar.db132d32 |
NANO-Antivirus | Trojan.Win32.Vidar.kvqhkk |
Rising | Trojan.Injector!8.C4 (CLOUD) |
F-Secure | Trojan.TR/Dropper.Gen |
DrWeb | Trojan.PWS.Vidar.69 |
TrendMicro | TrojanSpy.Win32.VIDAR.YXFBRZ |
McAfeeD | ti!1FED343AEAC0 |
Trapmine | suspicious.low.ml.score |
CTX | exe.trojan.vidar |
Sophos | Generic Reputation PUA (PUA) |
Detected | |
Avira | TR/Dropper.Gen |
Antiy-AVL | Trojan[PSW]/Win32.Vidar |
Kingsoft | Win32.Trojan-PSW.Vidar.ddq |
Xcitium | Malware@#25498mr2uj93o |
Microsoft | Trojan:Win32/Wacatac.B!ml |
GData | Win32.Trojan.Agent.DCX2AY |
Varist | W32/ABTrojan.XOQH-7073 |
AhnLab-V3 | Trojan/Win.Malware-gen.C5732316 |
McAfee | Artemis!EFC2DE49C53A |
DeepInstinct | MALICIOUS |
Malwarebytes | Malware.AI.4277945512 |
Ikarus | Trojan.Win64.Rozena |
TrendMicro-HouseCall | TrojanSpy.Win32.VIDAR.YXFBRZ |
Tencent | Win32.Trojan-QQPass.QQRob.Anhl |
huorong | HVM:Trojan/Injector.gen!E |
MaxSecure | Trojan.Malware.334343444.susgen |
Fortinet | W32/PossibleThreat |
AVG | Win32:Malware-gen |
Paloalto | generic.ml |