PULSE NAME
ThreatFox Hunt: Vidar IOCs - 2026-02-16
WHITE pduggusa 2026-02-16 Modified: 2026-03-18
53
IOCs
HIGH VOLUME
Automated ThreatFox hunt for Vidar indicators. 80 IOCs collected via Pattern 49 intelligence streaming. MITRE ATT&CK: T1555.003, T1539, T1005, T1041. Reference: https://analytics.dugganusa.com
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Vidar
Indicators of Compromise (53)
All URL domain FileHash-SHA256 FileHash-MD5 hostname
TYPEINDICATORDESCRIPTIONCREATED
URL https://74.0.48.100/ Vidar botnet_cc - ThreatFox ID: 1747746 2026-02-16
domain cyrex.cc Vidar payload_delivery - ThreatFox ID: 1747749 2026-02-16
FileHash-SHA256 94bca473a17a988566c7d5d94e8d6c63b167a8fbe1e8d7a97432ad0953d50d67 Vidar payload - ThreatFox ID: 1748457 2026-02-16
FileHash-MD5 806e14eb3fab9429adf17226be24fb3b Vidar payload - ThreatFox ID: 1748458 2026-02-16
FileHash-SHA256 046dffe23ed4259e949ba9116a3426dceb23aad9bd6bd22d44060e8b280bc551 Vidar payload - ThreatFox ID: 1748493 2026-02-16
FileHash-MD5 04feaad0b1d46c95bd19796e4f17b31a Vidar payload - ThreatFox ID: 1748494 2026-02-16
FileHash-SHA256 ba8513d09d7dc709e7bfed660efeb6f7be4227f58e60e5e9c49b91b5abb6c53a Vidar payload - ThreatFox ID: 1748508 2026-02-16
FileHash-MD5 97b3d06cabef1e153541fdba3a6f55a4 Vidar payload - ThreatFox ID: 1748509 2026-02-16
FileHash-SHA256 0688790625edef4500d4a4a9401b9d760578e7ff588a720196db322c702aa0f4 Vidar payload - ThreatFox ID: 1748520 2026-02-16
FileHash-MD5 156414d915e062a574bc45a2045969dd Vidar payload - ThreatFox ID: 1748521 2026-02-16
URL https://steamcommunity.com/profiles/76561198736378968 Vidar botnet_cc - ThreatFox ID: 1748821 2026-02-16
URL https://steamcommunity.com/profiles/76561199872628623 Vidar botnet_cc - ThreatFox ID: 1748822 2026-02-16
URL https://telegram.me/b0nn1r Vidar botnet_cc - ThreatFox ID: 1748823 2026-02-16
URL https://gbo.gadgetwalabd.com/ Vidar botnet_cc - ThreatFox ID: 1748824 2026-02-16
URL https://hil.gadgetwalabd.com/ Vidar botnet_cc - ThreatFox ID: 1748825 2026-02-16
URL https://gor.gadgetwalabd.com/ Vidar botnet_cc - ThreatFox ID: 1748826 2026-02-16
URL https://gbo.alpinematters.com/ Vidar botnet_cc - ThreatFox ID: 1748827 2026-02-16
URL https://hil.alpinematters.com/ Vidar botnet_cc - ThreatFox ID: 1748828 2026-02-16
URL https://gor.alpinematters.com/ Vidar botnet_cc - ThreatFox ID: 1748829 2026-02-16
URL https://jvz.gadgetwalabd.com/ Vidar botnet_cc - ThreatFox ID: 1748830 2026-02-16
URL https://jvz.alpinematters.com/ Vidar botnet_cc - ThreatFox ID: 1748831 2026-02-16
URL https://217.156.66.166/ Vidar botnet_cc - ThreatFox ID: 1748832 2026-02-16
URL https://65.21.165.10/ Vidar botnet_cc - ThreatFox ID: 1748833 2026-02-16
URL https://65.21.165.11/ Vidar botnet_cc - ThreatFox ID: 1748834 2026-02-16
URL https://46.225.86.191/ Vidar botnet_cc - ThreatFox ID: 1748835 2026-02-16
URL https://80.97.160.10/ Vidar botnet_cc - ThreatFox ID: 1748836 2026-02-16
URL https://91.98.229.254/ Vidar botnet_cc - ThreatFox ID: 1748837 2026-02-16
URL https://46.62.197.200/ Vidar botnet_cc - ThreatFox ID: 1748838 2026-02-16
URL https://46.225.118.134/ Vidar botnet_cc - ThreatFox ID: 1748839 2026-02-16
URL https://65.21.165.9/ Vidar botnet_cc - ThreatFox ID: 1748840 2026-02-16
URL https://65.21.165.12/ Vidar botnet_cc - ThreatFox ID: 1748841 2026-02-16
URL https://77.42.49.65/ Vidar botnet_cc - ThreatFox ID: 1748842 2026-02-16
URL https://65.21.165.8/ Vidar botnet_cc - ThreatFox ID: 1748843 2026-02-16
URL https://80.97.160.103/ Vidar botnet_cc - ThreatFox ID: 1748844 2026-02-16
URL https://65.21.165.13/ Vidar botnet_cc - ThreatFox ID: 1748845 2026-02-16
URL https://46.224.213.150/ Vidar botnet_cc - ThreatFox ID: 1748846 2026-02-16
URL https://46.225.136.75/ Vidar botnet_cc - ThreatFox ID: 1748847 2026-02-16
URL https://83.228.229.195/ Vidar botnet_cc - ThreatFox ID: 1748848 2026-02-16
URL https://88.198.214.231/ Vidar botnet_cc - ThreatFox ID: 1748849 2026-02-16
URL https://83.228.225.9/ Vidar botnet_cc - ThreatFox ID: 1748850 2026-02-16
URL https://74.0.48.157/ Vidar botnet_cc - ThreatFox ID: 1748851 2026-02-16
URL https://46.225.67.21/ Vidar botnet_cc - ThreatFox ID: 1748852 2026-02-16
URL https://83.147.192.235/ Vidar botnet_cc - ThreatFox ID: 1748853 2026-02-16
URL https://77.42.49.64/ Vidar botnet_cc - ThreatFox ID: 1748854 2026-02-16
URL https://77.42.49.63/ Vidar botnet_cc - ThreatFox ID: 1748855 2026-02-16
hostname gbo.gadgetwalabd.com Vidar botnet_cc - ThreatFox ID: 1748856 2026-02-16
hostname hil.gadgetwalabd.com Vidar botnet_cc - ThreatFox ID: 1748857 2026-02-16
hostname gor.gadgetwalabd.com Vidar botnet_cc - ThreatFox ID: 1748858 2026-02-16
hostname gbo.alpinematters.com Vidar botnet_cc - ThreatFox ID: 1748859 2026-02-16
hostname hil.alpinematters.com Vidar botnet_cc - ThreatFox ID: 1748860 2026-02-16
hostname gor.alpinematters.com Vidar botnet_cc - ThreatFox ID: 1748861 2026-02-16
hostname jvz.gadgetwalabd.com Vidar botnet_cc - ThreatFox ID: 1748862 2026-02-16
hostname jvz.alpinematters.com Vidar botnet_cc - ThreatFox ID: 1748863 2026-02-16