IOC Radar
TLP:WHITE4 IOCs

Vidar Infostealer Malware Returns with new TTPS – Detection & Response

SI
Security Investigation
Published February 24, 2023Original Report

Threat Actors

Malware Families

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYTurlaINFRASTRUCTURE176.113.115.17149.154.167.9978.46.254.12CAPABILITYVidarVICTIMunknown
Adversary(1)
Infrastructure(3)
Capability(1)
Victim

Attack Flow8 steps · MITRE ATT&CK mapped

Initial AccessTA0001·T1566
1/8
Phishing
ActionDeliver malware via phishing
Malware is distributed through spam emails or malicious websites, often disguised as free software downloads.

5W+H Threat Analysis

Analysis unavailable

Indicators of Compromise

Indicators of Compromise4

TypeIndicatorConfidenceScoreFirst Seen
IP176.113.115.17
c2intel-blogmalware
High
64
Jun 2, 26
IP149.154.167.99
intel-blogmalwarenetwork
High
58
Jun 2, 26
IP78.46.254.12
intel-blogmalwarenetwork
High
58
Jun 2, 26
SHA256a311b8137f8f47beb0c1cd3a79b97015b7d6a96074c165699ef1e2207d074556
exploitfile-hashintel-blog
Medium
53
Jun 2, 26

IOC Relationship Graph

IOC Relationship Graph4 total IOCs
IPSHA256
IP3SHA2561Actors1Malware1REPORTVidar Infostealer Malware TurlaVidar
scroll to zoom · drag to pan · click IOC to open