• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    Vidar Stealer known sample hashes (v2.0-v3.4) in file/process events

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Arnold Chan@slaz
    •updated 13 days ago•0•0•2

    This rule monitors for file and process creation events associated with known MD5 and SHA256 hashes linked to the Vidar infostealer malware.

    Microsoft Sentinel (KQL)

    Tags

    T1204.002 - Malicious FileTA0002 - ExecutionFile EventFile Executable DetectedProcess CreationMalware DetectedWindowsWindows Defender Atpkql

    Found in

    • Vidar Stealer Evolution: Virtual Machines and Custom CiphersLast updated 13 days ago
    • Vidar Stealer Evolution: Virtual Machines and Custom CiphersLast updated 13 days ago
    • Vidar Stealer Evolution: Virtual Machines and Custom CiphersLast updated 13 days ago
    • Vidar Stealer Evolution: Virtual Machines and Custom CiphersLast updated 13 days ago
    • Vidar Stealer Evolution: Virtual Machines and Custom CiphersLast updated 13 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?