Rewterz Threat Advisory – CVE-2021-3712 – Out-of-Bounds Read Vulnerability in OpenSSL
August 30, 2021Rewterz Threat Alert – WannaCry Ransomware – Active IOCs
August 30, 2021Rewterz Threat Advisory – CVE-2021-3712 – Out-of-Bounds Read Vulnerability in OpenSSL
August 30, 2021Rewterz Threat Alert – WannaCry Ransomware – Active IOCs
August 30, 2021Severity
High
Analysis Summary
Spyware.Vidar is a product that offers threat actors the option to set their preferences for the stolen information. Besides credit card numbers and passwords, Vidar can also scrape an impressive selection of digital wallets. This spyware can be spread using various campaigns. Vidar, which originally became active in late 2018, is a family of malware that operates primarily as an information stealer and is often observed as a precursor to ransomware deployment. It enables the capture and exfiltration of data from a system, including system information, browser data, and credentials
Impact
- Data exfiltration
- Information theft
- Exposure of sensitive data
Indicators of Compromise
MD5
- c8288e36713bd35ac1cb935be858354d
- efbe5cb437c6b83c094a2a384e5ced96
- 568a08d315e4f7b24aa62f96ddac7c22
- 44aca2b3036bf6fc887b71ef5eee6ec8
- d0278d81d6eef594f9d7858dad1e1ad3
- a603e7905b6ed6fb9c1ba45fa0fe2849
- f1da55c60adbc9b129fd3a81c2b272a2
SHA-256
- 3068463da4d3cb243d4d2c77c2acbb653a7378b1b1fd8811ae0fc0e77de0b5af
- 90b166a2fe38966f15be10d4b4c4d94a0b734f1163849afc8eae7a1b413569f2
- 8820519b8f90b97097604b0e852817a028c22ff86f60ec38ced8824df2c65710
- 7d85b2cd3745c4b6ba88e8ee72231913f70f859bf328cf4a2c0a9ea976042b61
- 93a902a32de4e465dc9c370dbe5b14f55be0f04b48516a2c71630a3e222bbb24
- ab8fbe37f313edae02e5bbeef6ea0249400319e4bb39932e5abe2854643601fb
- c86fabb9113e310ef7e0fbd3d96eae77ef78dbbc0512889c4d26f96970846625
SHA-1
- 45e04fa1c12028603bba48dc3f150eae29668279
- 73e1204e13a80ead9b7b605d35276f9b999a96a4
- 4c7174424d1c2a413d5a4ac1b9ab8596807072eb
- c274ad2cd8e405f44ade61fa034872e2a78ed933
- 2236f171229138ab4b7d95da6c359ca1b87c1b28
- cb8b4290e1facaf57cdfc830aa6cd07e2b28664f
- 0bee0661fada6afb7538b466477b9155f6edb873
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.