Rewterz Threat Advisory – Unknown Actor Using CLFS Log Files for Stealth – Active IOCs
September 3, 2021Rewterz Threat Alert – Qakbot (Qbot) Active Campaign – IoCs
September 5, 2021Rewterz Threat Advisory – Unknown Actor Using CLFS Log Files for Stealth – Active IOCs
September 3, 2021Rewterz Threat Alert – Qakbot (Qbot) Active Campaign – IoCs
September 5, 2021Severity
High
Analysis Summary
Spyware.Vidar is a product that offers threat actors the option to set their preferences for the stolen information. Besides credit card numbers and passwords, Vidar can also scrape an impressive selection of digital wallets. This spyware can be spread using various campaigns. Vidar, which originally became active in late 2018, is a family of malware that operates primarily as an information stealer and is often observed as a precursor to ransomware deployment. It enables the capture and exfiltration of data from a system, including system information, browser data, and credentials
Impact
- Data exfiltration
- Information theft
- Exposure of sensitive data
Indicators of Compromise
MD5
- c6e906dc4f85105e64c9a527e962ffc5
- 94eb21c5fb01f423d4d4fe4dbfa68f65
- e20eadf0f3063e0a73ca8569cd7c3c1b
- d11ee59b613ba4283775e163cc19f2b0
- 23bcdc132d1f2aaf8d248b6a5bd21801
SHA-256
- f1e43df9071ea84f39cd21fa7d3e4f1daf204e9fb04fce17e90aca5175064f52
- 07228c66b81b997d16f214f2854b5eff9103dd0015528b0d6b1b1f0f9700de8e
- 81f327dfcb337af8d576630d797059c5501a84cecb3612b69a2085cb2a74b494
- 465e0c7bd660ea8bc2a6fc4d0d556fe60b2ab94d99d377c26733bc777cb328f7
- a7cb6d861c75f36c32cb5a304b0d8d84b5bc0bedd7da2eb942e4d67288f7123b
SHA-1
- 63b912f03b5122c327bae060d8697e3197a9c9cb
- c907a583911c0766aecc8c2aec7b4f4b9910f398
- 995b8fecebb1ff10f9f6571c73d1ea49d5722477
- 94e972f2a47693dbfcd4cb9da3f5e785fd3d658a
- 2153acec77f4a57c621a3e38d523eb6df9b29134
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.