Rewterz Threat Alert – NetWire RAT Malware – Active IOCs
February 8, 2022Rewterz Threat Alert – Amadey Botnet – Active IOCs
February 8, 2022Rewterz Threat Alert – NetWire RAT Malware – Active IOCs
February 8, 2022Rewterz Threat Alert – Amadey Botnet – Active IOCs
February 8, 2022Severity
High
Analysis Summary
Vidar, which first appeared in late 2018, is a malware family that primarily acts as an information stealer and is frequently seen as a prelude to ransomware distribution. This malware takes data and distributes it as spam email, cracked commercial software, and keygen programs.
Vidar can scrape a wide range of digital wallets in addition to credit card data and passwords. Various campaigns can be used to propagate this malware. It allows data such as system information, browser data, and passwords to be captured and exfiltrated from a system. Vidar has also been seen as a secondary payload in ransomware attacks like STOP/DJVU.
Impact
- Data Exfiltration
- Information Theft
- Exposure of Sensitive Data
Indicators of Compromise
Filename
- CustomCursor[.]exe
- 9wp5ocjhz[.]dll
MD5
- d6f09c8cb3dd694b13efc1ba373c7f01
- 0785be512cb853a89e62ab7c2ecf58ba
SHA-256
- e55a07157505f3b50c11ec6d8894a6ea442818d59f1a64489e649f7fe6103cc4
- fd92fe8a4534bc6e14e177fee38a13f771a091fa6c7171fcee2791c58fbecf40
- bf671f4f672e07a224b649b53a97d8a3cb4c20b669e464bbb5525cbcbe6721c1
SHA-1
- 2e513ce4696396d801528cc8d819238460725756
- 5e7d92dfdf2caef7f80f65cd009d60a77d9d651d
Remediation
- Block all the threat indicators at your respective controls.
- Search for IOCs in your environment.