Concrete signature match: Trojan - Appears legitimate but performs malicious actions for 32-bit Windows platform, family Vidar
This detection identifies a variant of the Vidar info-stealer trojan, a highly dangerous malware designed to exfiltrate sensitive data. Vidar typically steals credentials, cryptocurrency wallet information, browser data, and system details from compromised machines.
No specific strings found for this threat
rule Trojan_Win32_Vidar_AAQ_2147900985_0
{
meta:
author = "threatcheck.sh"
detection_name = "Trojan:Win32/Vidar.AAQ!MTB"
threat_id = "2147900985"
type = "Trojan"
platform = "Win32: Windows 32-bit platform"
family = "Vidar"
severity = "Critical"
info = "MTB: Microsoft Threat Behavior"
signature_type = "SIGNATURE_TYPE_PEHSTR_EXT"
threshold = "1"
strings_accuracy = "Low"
strings:
$x_1_1 = {8b c8 33 d2 8b c7 f7 f1 8b 45 ?? 8b 4d fc 8a 04 02 32 04 31 47 88 06 3b 7d 10 72} //weight: 1, accuracy: Low
condition:
(filesize < 20MB) and
(all of ($x*))
}d71b1e8faa5f84fe655f434fbda14f03b36e1a65d3426f8bd61c1797a35a1d13d22d60c754eb0bd1625d28dd7efaf4ca85fc034132831e9ece586f6c67bb59898fca38a5b26aa4157ad169804744c4806e332fd0f7c98aa256f4ac746a63707bImmediately isolate the infected system from the network. Perform a full scan with up-to-date antivirus software and remove all detected malicious files. Review system logs for signs of further compromise or lateral movement, and reset all potentially compromised credentials, especially for online accounts and local services.