Rewterz Threat Advisory – LockFile Ransomware Hacked Multiple Microsoft Exchange Servers
August 22, 2021Rewterz Threat Alert – NJRAT – Active IOCs
August 23, 2021Rewterz Threat Advisory – LockFile Ransomware Hacked Multiple Microsoft Exchange Servers
August 22, 2021Rewterz Threat Alert – NJRAT – Active IOCs
August 23, 2021Severity
High
Analysis Summary
Spyware.Vidar is a product that offers threat actors the option to set their preferences for the stolen information. Besides credit card numbers and passwords, Vidar can also scrape an impressive selection of digital wallets. This spyware can be spread using various campaigns. Vidar, which originally became active in late 2018, is a family of malware that operates primarily as an information stealer and is often observed as a precursor to ransomware deployment. It enables the capture and exfiltration of data from a system, including system information, browser data, and credentials
Impact
- Data exfiltration
- Information theft
- Exposure of sensitive data
Indicators of Compromise
MD5
- f3c58fb85a3d39ec45a78b7fbd11021b
- f410aa20278033a2158bc670a4d341a8
- 5be9bfad00f219b0d219261448a57bda
- 724f01298e921f1f7362af6b1bc31642
SHA-256
- 4f4c2c9bdfef8a8cfbe2c8f84bf12cc86f26f59d54c277dab39f4c5e92948708
- 4d5c0f48a8ce95adc60131576a3b2a58101e382e9299d5b7ee120508a88f73f3
- 996c8bc5c0ce6a773b8d401860ea39c714485bc6e9e58d75eaff99c26e384609
- 8174d7d1e9ccf99d8a0164e39dbb7df725cbd710cf2f611d3ca4f2fdeb434535
SHA-1
- 473d3c0eba1155217fa21dc8b35155516e52acfd
- fe81a5c5cc0ddbc59686bd14b7314889523f0015
- 0600955c1006e2569a1e396c0f086e62e8521fdb
- e892f38da2f930133cf67533e592ded56b7d6154
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.