Rewterz Threat Alert – Trickbot Malware – Active IOCs
September 6, 2021Rewterz Threat Alert – Remcos RAT – Active IOCs
September 6, 2021Rewterz Threat Alert – Trickbot Malware – Active IOCs
September 6, 2021Rewterz Threat Alert – Remcos RAT – Active IOCs
September 6, 2021Severity
High
Analysis Summary
Spyware.Vidar is a product that offers threat actors the option to set their preferences for the stolen information. Besides credit card numbers and passwords, Vidar can also scrape an impressive selection of digital wallets. This spyware can be spread using various campaigns. Vidar, which originally became active in late 2018, is a family of malware that operates primarily as an information stealer and is often observed as a precursor to ransomware deployment. It enables the capture and exfiltration of data from a system, including system information, browser data, and credentials
Impact
- Data exfiltration
- Information theft
- Exposure of sensitive data
Indicators of Compromise
MD5
- 65aaabe043d722d07305bf5b8f36b877
- 073c1787d055081560ebebe789eb1282
- c1126df826aff5add7dca523382da558
SHA-256
- 08f10bfb643c86336ab0275c39d4341a206fa4c4d5d169860ed41e7aa09f56e0
- 907c112beb537b9bdc86aa35fa1bb7eabd2adb88193f4eb505f1665086c7d1d9
- afaa0f7e859fdd8e68f00d6616e8e0dddf8c33331b47aa0987fc60118810574b
SHA-1
- 756ea1324eedaf1549553c413aeb1fefd69e53a5
- e8729a8253ba425ea73c0c055f62d83eeb84bc58
- 042f32e048a1952c49f3a30c5c78b6755264f94b
URL
- https[:]//securebiz[.]org/dl/build2[.]exe
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.