Tarnkappe.info · @tarnkappeinfo
1994 followers · 4313 posts · Server social.tchncs.de
mithrandir · @mithrandir
52 followers · 117 posts · Server defcon.social

A few weeks ago I found a malicious Google Ad leading to the Vidar stealer.

The payload was hosted on a previously long dormant GitHub account, github.com/hgmbln.

After years of no activity, they forked a legitimate project and added Vidar as a release. In the last two days, they have done the same, this time adding an unknown malware as the release.

This account was reported, but is still active.

I uploaded a sample to Malshare.
malshare.com/sample.php?action

#intel #vidar #malvertising

Last updated 1 year ago

Randy :donor: · @rmceoin
130 followers · 376 posts · Server infosec.exchange

Ah, it's according to Triage. Had to get use the payload it grabbed.

104.156.149[.]33/yes/193TIuetnayqZtaKBfkSOsoCtZH.exe

tria.ge/230207-1p4esafc2v/beha

#vidar

Last updated 2 years ago

Randy :donor: · @rmceoin
95 followers · 340 posts · Server infosec.exchange

@cyberlibrarian Agreed, it's risky business for users who are not already familiar with what the software download site should look like and the correct URL for it.

I got the sample. It looks like most of the samples I get recently. A ZIP file with lots of unused files and a very large EXE. Both of those alone make it harder on the current sandboxes. So I just extract the EXE, truncate it, then lob it into a variety of sandboxes.

Joe Sandbox was doing great at identifying them, but ran out of my monthly quota 😭​

Your sample comes back as

tria.ge/230130-3erpcaeg8s/beha

#vidar

Last updated 2 years ago

Colin Cowie · @th3_protoCOL
634 followers · 171 posts · Server infosec.exchange

Day 1️⃣​1️⃣​ of - Browser Extensions Targeted by Vidar

🔗​ github.com/colincowie/100DaysO

For today's rule I took a look at the 1.9 sample mentioned in @teamcymru_S2 's 🔥​ research:
team-cymru.com/post/darth-vida

#100DaysofYARA #infostealer #vidar

Last updated 2 years ago

· @Glacius
89 followers · 7 posts · Server infosec.exchange

Hey :)

We published a detailed report on infrastructure management, explaining how they are working. We also share malware configuration extractor over the C2, backend IPs, etc:

team-cymru.com/post/darth-vida

Happy Hunting and feedback warmly welcomed 😊

@teamcymru_S2

#vidar

Last updated 2 years ago

RayManD · @raymand
3 followers · 101 posts · Server maston.grupotd.nat.cu

RT @elhackernet
🚨 Mucho cuidado:

Utilizan falsos anuncios en Google (enlaces patrocinados) de populares programas como OBS, KMPlayer, VirtualBox, Blender 3D, Gimp, LibreOffice para hackear y robar cuentas de Twitter, YouTube, etc

#aurora #vidar #malware #stealer

Last updated 2 years ago

[Threatview.io] 🕵️‍♂️Malware using as C2

⚙️tria.ge/230118-sey4babd63
⚠️ C2: 95.216.178[.]160



#vidar #tiktok #threatintel #cti #cybersecurity

Last updated 2 years ago

Henrique · @henriquetguedes
143 followers · 191 posts · Server mstdn.social

RT @1ZRR4H@twitter.com

🚨 Continuan las campañas de malware vía Google Ads, ahora stealer (botnet 698) con archivo de casi 300MB, imitando a , , y .

/aduducity.org
/qiupm.org
/blenderno.org
/tradervwiev.org

C2:
91.107.158.249
78.47.228.65

🐦🔗: twitter.com/1ZRR4H/status/1614

#tradingview #Blender #Gimp #AudaCity #vidar

Last updated 2 years ago

Marc Almeidaˎˊ˗ · @cibernicola
155 followers · 1260 posts · Server mastodon.social

RT @1ZRR4H@twitter.com

🚨 Continuan las campañas de malware vía Google Ads, ahora stealer (botnet 698) con archivo de casi 300MB, imitando a , , y .

/aduducity.org
/qiupm.org
/blenderno.org
/tradervwiev.org

C2:
91.107.158.249
78.47.228.65

🐦🔗: twitter.com/1ZRR4H/status/1614

#vidar #audacity #gimp #blender #tradingview

Last updated 2 years ago

da_667 · @da_667
3305 followers · 136 posts · Server infosec.exchange

Saw this today on birdsite - apparently there's a massive vidar stealer campaign with 1300+ domains registered with a good amount of typo squatting going on.

gist.github.com/qbourgue/a8187

credit to @crep1x@twitter.com

For the time being, they are all registered to a single IP address oddly enough, so instead of vomiting out a massive amount of DNS rules today, I opted to create a rule that catches the query response with the IP address in question.

Additionally, here is triage sandbox run: tria.ge/230107-vnc9bahd7x/beha

Finally, suricata sid 2036316 is a part of the ET OPEN ruleset, and will detect Arkei/Vidar/Mars stealer variants -- tested against the pcap generated from the triage run.

Happy Monday, MFers.

#threatintel #malware #infostealer #snort #suricata #vidar #ioc #iocsharing

Last updated 2 years ago

Stef Rand · @techieStef
134 followers · 7 posts · Server infosec.exchange

Really great article from the Sekoia.io team just dropped, looking at the infostealer activity that's been crazy-busy lately.

blog.sekoia.io/unveiling-of-a-

The Red Canary intel team just saw some of this activity earlier in the week. Our sample was Themida-packed V2, but Sekoia also reports distributed this way which surprises me none.

Anyway, really good and very timely article, well worth your time. There were a couple hundred of these samples uploaded to VT over the holidays, and those were just the ones I ran across without looking super hard. There's a ton of this out there right now.

#raccoon #vidar

Last updated 2 years ago

Brad · @malware_traffic
1961 followers · 67 posts · Server infosec.exchange

2022-12-29 (Thursday) - Getting ready to shut down for the evening, and I wanted to try one more time.

This time I set up my Windows lab computer as a Brazil host with Portuguese language.

I saw aanother Google ad, this time to a fake AnyDesk page at computer-remote[.]site.

This time the malware was an variant (/#OkiStealer/#MarsStealer/whatever its morphed into now).

Download link: hxxps://computer-remote[.]site/download.php

Download link redirects to aip file hosted on Dropbox at: hxxps://dl.dropboxusercontent[.]com/s/hpkf0my15vts98l/SetupMain.zip?dl=0

Couldn't get the full zip uploaded to Malware Bazaar, because it was too big. Got it sent to VirusTotal, though.

- virustotal.com/gui/file/501830

51.8 MB zip download, containing a bunch of crap and a 624 MB Windows EXE file.

I carved the extracted EXE to remove the padding, and the carved sample is available at: bazaar.abuse.ch/sample/2e25487

Analysis of the carved EXE:

- tria.ge/221230-fk3mgaa
- app.any.run/tasks/80236e10-611

Even though my host was set up for Brazil Portuguese, the fake AnyDesk page and downloaded malware were in English.

#arkeistealer #vidar

Last updated 2 years ago

Tarnkappe.info · @tarnkappeinfo
1732 followers · 3967 posts · Server social.tchncs.de

Vidar Audio Hammer v1.0.0 VST3 AU AAX WiN Mac [FREE]
HAMMER is a hybrid modern and vintage compressor/limiter.

And best of all, the plugin is free.

This plug-in is compatible with both Windows and Mac and combines ease of use
testblog.music-society.de/vida
-VST3-AAX-AU

#vst #aax #applesilicon #au #compressor #easy #free #hybrid #intel #l #limiter #macOS #mix #other #rms #vidar #vintage #vst3 #windows #x64

Last updated 2 years ago

Pretty sneaky for malware to hide next stage IP in Gamer Name /Gamer profile on Steam Community.

Malware connects to steamcommunity to get next stage.

Initial vector is on Discord, reported abuse now on URLHaus
urlhaus.abuse.ch/url/2431882/

Payload

bazaar.abuse.ch/sample/837d4db

#vidar #steam #steamcommunity #malware #infosec #cybersecurity

Last updated 2 years ago

Bandar Baru · @bandarbaru_1
31 followers · 502 posts · Server mastodon.social

Kalau program itu berbayar, pertama lihat dulu apakah ada alternatif lain yang gratis dan sumber terbuka (FOSS)?

Jika tidak ada atau merasa alternatif FOSS kurang memuaskan, maka belilah lisensinya.

RT @CKsTechNews@twitter.com

Tutorial Videos Spreading and

The new campaign highlights the fact that downloading cracked software is bad news.

hackread.com/youtube-videos-vi

🐦🔗: twitter.com/CKsTechNews/status

#youtube #vidar #raccoon #malware

Last updated 2 years ago

CK's Technology News · @CKsTechnologyNews
1534 followers · 31987 posts · Server mastodon.social

Tutorial Videos Spreading and

The new campaign highlights the fact that downloading cracked software is bad news.

hackread.com/youtube-videos-vi

#youtube #vidar #raccoon #malware

Last updated 2 years ago