Rewterz Threat Alert – SquirrelWaffle Malware- Active IOCs
November 17, 2021Rewterz Threat Alert – Dridex Banking Trojan – Active IOCs
November 17, 2021Rewterz Threat Alert – SquirrelWaffle Malware- Active IOCs
November 17, 2021Rewterz Threat Alert – Dridex Banking Trojan – Active IOCs
November 17, 2021Severity
High
Analysis Summary
Spyware.Vidar is a product that offers threat actors the option to set their preferences for the stolen information. Besides credit card numbers and passwords, Vidar can also scrape an impressive selection of digital wallets. This spyware can be spread using various campaigns. Vidar, which originally became active in late 2018, is a family of malware that operates primarily as an information stealer and is often observed as a precursor to ransomware deployment. It enables the capture and exfiltration of data from a system, including system information, browser data, and credentials.
Impact
- Data Exfiltration
- Information Theft
- Exposure of Sensitive Data
Indicators of Compromise
MD5
- ba5785dc88969bde332773d3ecd5013d
SHA-256
- 01df68bb9e9527e6179f2d4ad78d82638eb7a5f47839425ed457a36eb5088693
- 3b8b83f08152b2eaf427e8a75785d7f249c9a6740900478fa729294652ed9706
- 7ba62b70626c0c8a6891a752b19733521e947b303baa51e718f0ec202d5f1d19
- babf65b4370b3137a720a3c18c26842475abdecb42b3fb5e1a95f497e9b4c42f
SHA-1
- 1881a48180782fcbe4127c59a1acefaea332579a
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.