

Rewterz Threat Alert – Trickbot Malware – Active IOCs
June 28, 2022
Rewterz Threat Alert – AZORult Malware – Active IOCs
June 28, 2022
Rewterz Threat Alert – Trickbot Malware – Active IOCs
June 28, 2022
Rewterz Threat Alert – AZORult Malware – Active IOCs
June 28, 2022Severity
High
Analysis Summary
Vidar, which first appeared in late 2018, is a malware family that primarily acts as an information stealer and is frequently seen as a prelude to ransomware distribution. This malware takes data and distributes it as spam email, cracked commercial software, and keygen programs.
Vidar can scrape a wide range of digital wallets in addition to credit card data and passwords. Various campaigns can be used to propagate this malware. It allows data such as system information, browser data, and passwords to be captured and exfiltrated from a system. Vidar has also been seen as a secondary payload in ransomware attacks like STOP/DJVU.
Impact
- Data Exfiltration
- Information Theft
- Exposure of Sensitive Data
Indicators of Compromise
MD5
- 7fd3af0006e6f8c1b3bf8d476ab47aa4
- 17a086e3eff45b0b6d5af65e4c86946d
- 53dec7a3a6418bbc55d20e40e97a224c
SHA-256
- 28aa592120538084022dacf4fa11bba3f98b9aec440390660b6ff277cc5c27ad
- c758ce5104c656e43909365e39bb6cec452475535798ee44f5e4e13d750a0035
- 502f0a6587cf2d084e98f5edc12192e1ca37515bdf7364511415d615be2e6aa7
SHA-1
- 633203b7ff94e90d5c17e60dcf12627bb36fbbf8
- 031372e476bb75139c37ca61f4c6334948fd6ab8
- b6427092966218261138ad15a911f4cca5d9a69b
Remediation
- Block all the threat indicators at your respective controls.
- Search for IOCs in your environment.