836ce1411f26919f8fb95548d03c2f4dfd658fc525dfe21c7be8ed65f81a5957

Classification: Malicious

836ce1411f26919f8fb95548d03c2f4dfd658fc525dfe21c7be8ed65f81a5957 is a malicious file sample. Reported by 2 threat sources, last seen 2026-09-02.

Detection summary

  • 64 antivirus detections
  • 4 IDS alerts
  • 4 processes observed
  • 5 contacted hosts
  • 4 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2024-10-01 15:00:03 2026-09-02 19:45:03 malicious-activity
Vidar ThreatFox Abuse.ch 2024-10-01 17:42:01 2024-10-03 17:21:38

Tags

win.vidar evasive infostealer

Sample information

Filenames
836ce1411f26919f8fb95548d03c2f4dfd658fc525dfe21c7be8ed65f81a5957, 66fbfccd837ac_vadggdsa.exe
File type
PE32 executable (console) Intel 80386 Mono/.Net as ...
Size
423840 bytes
MD5
237af39f8b579aad0205f6174bb96239
SHA-1
7aad40783be4f593a2883b6a66f66f5f624d4550
SHA-256
836ce1411f26919f8fb95548d03c2f4dfd658fc525dfe21c7be8ed65f81a5957
First indexed
2024-10-01 14:40:23
Last updated
2026-09-02 19:45:03

Antivirus detections

EngineDetection
AhnLab-V3Trojan/Win32.HDC.C379069
ArcabitTrojan.PasswordStealer.MSILHeracles.8
AviraTR/AD.Stealc.decxn
BitDefenderGen:Variant.PasswordStealer.MSILHeracles.8
BkavW32.AIDetectMalware.CS
CTXexe.unknown.msilheracles
CrowdStrikewin/malicious_confidence_90% (D)
CylanceUnsafe
DeepInstinctMALICIOUS
ESET-NOD32a variant of MSIL/GenKryptik.HCGG
Elasticmalicious (high confidence)
EmsisoftGen:Variant.PasswordStealer.MSILHeracles.8 (B)
F-SecureTrojan.TR/AD.Stealc.decxn
FireEyeGeneric.mg.237af39f8b579aad
FortinetMSIL/GenKryptik.HCCC!tr
GoogleDetected
GridinsoftSpy.Win32.Gen.tr
IkarusTrojan-Spy.LummaStealer
KingsoftMSIL.Trojan.Crypt.gen
LionicTrojan.Win32.Generic.4!c
McAfeeDti!836CE1411F26
MicroWorld-eScanGen:Variant.PasswordStealer.MSILHeracles.8
MicrosoftTrojan:MSIL/RedlineStealer.AMH!MTB
Paloaltogeneric.ml
PandaTrj/Chgt.AD
RisingMalware.Obfus/[email protected] (RDM.MSIL2:PtT+dOajkNrOH2HpUBDHiQ)
SentinelOneStatic AI - Malicious PE
SophosMal/Generic-S
SymantecML.Attribute.HighConfidence
TrendMicroTrojan.Win32.PRIVATELOADER.YXEJAZ
TrendMicro-HouseCallTrojan.Win32.PRIVATELOADER.YXEJAZ
VaristW32/MSIL_Kryptik.LOU.gen!Eldorado
huorongTrojan/MSIL.Agent.li
ALYacGen:Variant.Jalapeno.18571
AVGWin32:PWSX-gen [Trj]
AlibabaTrojan:MSIL/RedlineStealer.0084c16a
ArcabitTrojan.Jalapeno.D488B
AvastWin32:PWSX-gen [Trj]
BitDefenderGen:Variant.Jalapeno.18571
CTXexe.trojan.msil
DrWebTrojan.PWS.Stealer.40211
EmsisoftGen:Variant.Jalapeno.18571 (B)
GDataGen:Variant.Jalapeno.18571
IkarusTrojan.MSIL.Krypt
K7AntiVirusRiskware ( 00584baa1 )
K7GWRiskware ( 00584baa1 )
KasperskyHEUR:Trojan.MSIL.Stelpak.gen
LionicTrojan.Win32.Stelpak.4!c
MalwarebytesTrojan.Crypt.MSIL
McAfeeArtemis!237AF39F8B57
MicroWorld-eScanGen:Variant.Jalapeno.18571
NANO-AntivirusTrojan.Win32.Stealc.kspoka
RisingMalware.Obfus/[email protected] (RDM.MSIL2:PtT+dOajkNrOH2HpUBDHiQ)
SkyhighArtemis!Trojan
SophosMal/MSIL-WA
SymantecTrojan.Gen.MBT
TencentTrojan.Msil.Stelpak.16001446
VBA32TScope.Trojan.MSIL
VIPREGen:Variant.Jalapeno.18571
VirITTrojan.Win32.MSIL.FXX
XcitiumMalware@#k14yzzae2c6r
ZillyaTrojan.GenKryptik.Win32.982222
ZoneAlarmHEUR:Trojan.MSIL.Stelpak.gen
alibabacloudTrojan[dropper]:MSIL/Stelpak.gyf

Network contacts

23.37.16.240 149.154.167.99 192.124.249.22 192.124.249.36 49.12.197.9

DNS requests

crl.godaddy.com ocsp.godaddy.com steamcommunity.com t.me

Process list

NameCommand line
66fbfccd837ac_vadggdsa.exe
RegAsm.exe
cmd.exe/c timeout /t 10 & del /f /q "%WINDIR%\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe" & rd /s /q "%ALLUSERSPROFILE%\BGDBAKFCFHCG" & exit
timeout.exetimeout /t 10