Rewterz Threat Alert – LokiBot Malware – Active IOCs
September 14, 2021Rewterz Threat Alert – AZORult Malware – Active IOCs
September 14, 2021Rewterz Threat Alert – LokiBot Malware – Active IOCs
September 14, 2021Rewterz Threat Alert – AZORult Malware – Active IOCs
September 14, 2021Severity
High
Analysis Summary
Spyware.Vidar is a product that offers threat actors the option to set their preferences for the stolen information. Besides credit card numbers and passwords, Vidar can also scrape an impressive selection of digital wallets. This spyware can be spread using various campaigns. Vidar, which originally became active in late 2018, is a family of malware that operates primarily as an information stealer and is often observed as a precursor to ransomware deployment. It enables the capture and exfiltration of data from a system, including system information, browser data, and credentials
Impact
- Data exfiltration
- Information theft
- Exposure of sensitive data
Indicators of Compromise
MD5
- 81f1096418f40a2d2fa5dfe56d625991
- 7419b76a053b660459e1edcf1dfef302
- 827b58b15eb27e42119f57876f4c819a
SHA-256
- 259bfc6ced97f6630c9b50045dd94c786ff3ccf705f14180169f8dafcdf82b98
- 941478d129063e71885f97791339a49c58c72991ccc8309734f12ef60aee5530
- 7b0409caebe92c8b64a6f3b3f071bf7829eb98e4904d077b291695e2b2619413
SHA-1
- 852a76e2ee3ed2cd20057aec628833884df0a063
- 43cab9f90509553f67eaed5b7321e358227cbe4f
- 211c7f114abec4e93fd2c1a9df556d9f4ae222cc
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.