

Rewterz Threat Update – 1.2 Million Users Affected by GoDaddy Data Breach
November 23, 2021
Rewterz Threat Alert – Quasar RAT – Active IOCs
November 23, 2021
Rewterz Threat Update – 1.2 Million Users Affected by GoDaddy Data Breach
November 23, 2021
Rewterz Threat Alert – Quasar RAT – Active IOCs
November 23, 2021Severity
High
Analysis Summary
Spyware.Vidar is a product that offers threat actors the option to set their preferences for the stolen information. Besides credit card numbers and passwords, Vidar can also scrape an impressive selection of digital wallets. This spyware can be spread using various campaigns. Vidar, which originally became active in late 2018, is a family of malware that operates primarily as an information stealer and is often observed as a precursor to ransomware deployment. It enables the capture and exfiltration of data from a system, including system information, browser data, and credentials.
Impact
- Data Exfiltration
- Information Theft
- Exposure of Sensitive Data
Indicators of Compromise
MD5
- 65ccf6e936bf042fa117219da6f92838
SHA-256
- 7eee8f72e8004f0a7e42392106f5755ea074c9d624e30de76037660365c7f890
- 5f5f7d6ded684b2ae4c610dde0ea7e81408001309484699472c0b920f31e588f
- 2618c33218c0a9132720b395b3c85da49b8f9bead87ad531ad0ae8c60db767c0
- b01d50ac5c56fb7a45b8b9b66ff3cf7e4f278257dd01619099db7ac7f284bc48
- b32bf66687b4cbb9a49cba99c474be9cb690c6c7098dd5588cae3d5ab1b329d5
SHA-1
- 52f3fa111c8ba2164fdf945b69343275b549b8f7
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.