Rewterz Threat Alert – XLoader Malware – Active IOCs
November 24, 2021Rewterz Threat Alert – Hancitor InfoStealer – Active IOCs
November 24, 2021Rewterz Threat Alert – XLoader Malware – Active IOCs
November 24, 2021Rewterz Threat Alert – Hancitor InfoStealer – Active IOCs
November 24, 2021Severity
High
Analysis Summary
Spyware.Vidar is a product that offers threat actors the option to set their preferences for the stolen information. Besides credit card numbers and passwords, Vidar can also scrape an impressive selection of digital wallets. This spyware can be spread using various campaigns. Vidar, which originally became active in late 2018, is a family of malware that operates primarily as an information stealer and is often observed as a precursor to ransomware deployment. It enables the capture and exfiltration of data from a system, including system information, browser data, and credentials.
Impact
- Data Exfiltration
- Information Theft
- Exposure of Sensitive Data
Indicators of Compromise
MD5
- f67b9d830713a86a21e0d0131915ccd5
SHA-256
- ac5b0acfd212a0bf9dc3d0749b89d53f96054991d2d20f4e5e9c1727f0154c43
- 448e0ee938a14ef0f54cd6aaa94e2aa58f26558aaef43bcc1c7f6fe9c603ae3c
- 0a00daf20092ce969b6fc662aaa4be4b93c665f8aa0ba3ad68fde6e00ad11e06
- 627707cb5c6b167656148da01dcd9f4bcce30b9cd04f58129d4e871c48e8d08f
SHA-1
- 94fb2d1b3f636c878a0625d969de69218c265339
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.