Rewterz Threat Alert – APT10 MenuPass – Active IOCs
August 25, 2021Rewterz Threat Alert – APT32 Ocean Lotus – Active IOCs
August 25, 2021Rewterz Threat Alert – APT10 MenuPass – Active IOCs
August 25, 2021Rewterz Threat Alert – APT32 Ocean Lotus – Active IOCs
August 25, 2021Severity
High
Analysis Summary
Spyware.Vidar is a product that offers threat actors the option to set their preferences for the stolen information. Besides credit card numbers and passwords, Vidar can also scrape an impressive selection of digital wallets. This spyware can be spread using various campaigns. Vidar, which originally became active in late 2018, is a family of malware that operates primarily as an information stealer and is often observed as a precursor to ransomware deployment. It enables the capture and exfiltration of data from a system, including system information, browser data, and credentials
Impact
- Data exfiltration
- Information theft
- Exposure of sensitive data
Indicators of Compromise
MD5
- 405f32d7d1c647b66c3f6b9a5355791a
- 42f5415bc69a47f38c87ec95a6895f69
- 88f9ea3b09d41603f4fa8b46875910c3
- 7bd48cb14f16818b09dd943c6902b113
- 3f9d188595f40d91b8e7c4634f89c82a
- cd75d492cb927685998e3160cf1ae09c
- c07a49b77c116949efedc6f443957ae3
- 28b20d90d1efa7800697bc323b01a378
- bc0fa9eea5e4c3a2fa4a8a11516e51cf
- c313ddb7df24003d25bf62c5a218b215
SHA-256
- 3b4c4c4e34e28d067dce529db28cd17d85365bbf0934afead71aa034a115163a
- 129dfae761bb3e09c9afc435bee0d1a40c5c0143b0840d2250f44525b4e8f933
- dc68a6f319959835a59fe9da990df9ba3b9b567325b5e6ef62629ffe7f5ec4bf
- bd03bf80e1f36703f7912c33fb3fc84e9499a5e702a72b4ad260d320c1bf51ae
- 1e9fdba9e84dedcfdc3f69862350e56ffe8afbdcde704ad23959435b7fab79d3
- c5575331085dff0c29ab58cd31d484d714729f5eb2b351d2adea81b0e7966660
- b22b057cc2020cfb5cf00f4d8e54a5d4f709babbdc2a03b9e21b38fee73c80be
- cdc9a15859638b1abfa09483088b78bbf51ae92c6f9434a92f1ea7d93122de69
- 67148bf6ac6d459c6e657905e0954c5830976b88917ce10b4e8ee2e8f183bd00
- e3bc81a59fc45dfdfcc57b0078437061cb8c3396e1d593fcf187e3cdf0373ed1
SHA-1
- 330a7dbf718ae8549f347ac6f218ec2c8f1a4bb2
- 426669bd22b2691643ae985f909e287d6ee4a5fa
- 42a4c6ded84467f59e8a0e51f2b6295bb0171994
- 4cffb213093fbe5c383fe2e65e7e01e50bcd57c1
- c67a3ac1dc5a45ac5ca84b035c785ffe0fc1c290
- 8ed124ddc8a7861df1822196d0929908ee010528
- 456197add38fe693d86d9a5254c966489bdc2d78
- 20a3404b7e17b530885fa0be130e784f827986ee
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.