PULSE NAME
ThreatFox Hunt: Vidar IOCs - 2026-01-17
WHITE pduggusa 2026-01-17 Modified: 2026-02-16
19
IOCs
MEDIUM VOLUME
Automated ThreatFox hunt for Vidar indicators. 22 IOCs collected via Pattern 49 intelligence streaming. MITRE ATT&CK: T1555.003, T1539, T1005, T1041. Reference: https://analytics.dugganusa.com
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Vidar
Indicators of Compromise (19)
All URL hostname
TYPEINDICATORDESCRIPTIONCREATED
URL https://tth.sekershuk.com/ Vidar botnet_cc - ThreatFox ID: 1732659 2026-01-17
URL https://tth.123230.xyz/ Vidar botnet_cc - ThreatFox ID: 1732660 2026-01-17
URL https://mxx.sekershuk.com/ Vidar botnet_cc - ThreatFox ID: 1732661 2026-01-17
URL https://mxx.123230.xyz/ Vidar botnet_cc - ThreatFox ID: 1732662 2026-01-17
URL https://178.236.254.147/ Vidar botnet_cc - ThreatFox ID: 1732663 2026-01-17
URL https://138.226.237.198/ Vidar botnet_cc - ThreatFox ID: 1732664 2026-01-17
URL https://138.226.236.212/ Vidar botnet_cc - ThreatFox ID: 1732665 2026-01-17
hostname mxx.sekershuk.com Vidar botnet_cc - ThreatFox ID: 1732666 2026-01-17
hostname mxx.123230.xyz Vidar botnet_cc - ThreatFox ID: 1732667 2026-01-17
hostname tth.sekershuk.com Vidar botnet_cc - ThreatFox ID: 1732668 2026-01-17
hostname tth.123230.xyz Vidar botnet_cc - ThreatFox ID: 1732669 2026-01-17
URL https://kle.sekershuk.com/ Vidar botnet_cc - ThreatFox ID: 1733585 2026-01-17
URL https://kle.123230.xyz/ Vidar botnet_cc - ThreatFox ID: 1733586 2026-01-17
URL https://poc.sekershuk.com/ Vidar botnet_cc - ThreatFox ID: 1733587 2026-01-17
URL https://poc.123230.xyz/ Vidar botnet_cc - ThreatFox ID: 1733588 2026-01-17
hostname poc.sekershuk.com Vidar botnet_cc - ThreatFox ID: 1733589 2026-01-17
hostname poc.123230.xyz Vidar botnet_cc - ThreatFox ID: 1733590 2026-01-17
hostname kle.sekershuk.com Vidar botnet_cc - ThreatFox ID: 1733591 2026-01-17
hostname kle.123230.xyz Vidar botnet_cc - ThreatFox ID: 1733592 2026-01-17