This hunt detects adversary activity involving the Vidar information stealer by monitoring for matches against a curated set of 90 known Indicators of Compromise (IOCs). Proactively hunting for these signals in Azure Sentinel is critical to identify early-stage data exfiltration attempts and prevent potential credential theft before the malware establishes persistence on compromised endpoints.
Malware Family: Vidar Total IOCs: 90 IOC Types: ip:port, url, domain
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| ip:port | 185[.]181[.]8[.]182:443 | botnet_cc | 2026-08-31 | 100% |
| ip:port | 46[.]224[.]87[.]76:443 | botnet_cc | 2026-08-31 | 100% |
| ip:port | 62[.]238[.]126[.]31:443 | botnet_cc | 2026-08-31 | 100% |
| ip:port | 185[.]229[.]225[.]31:443 | botnet_cc | 2026-08-31 | 100% |
| ip:port | 2[.]29[.]15[.]172:443 | botnet_cc | 2026-08-31 | 100% |
| ip:port | 2[.]28[.]53[.]167:443 | botnet_cc | 2026-08-31 | 100% |
| ip:port | 168[.]119[.]61[.]136:443 | botnet_cc | 2026-08-31 | 100% |
| ip:port | 91[.]98[.]236[.]89:443 | botnet_cc | 2026-08-31 | 100% |
| ip:port | 77[.]42[.]69[.]149:443 | botnet_cc | 2026-08-31 | 100% |
| ip:port | 2[.]28[.]55[.]31:443 | botnet_cc | 2026-08-31 | 100% |
| ip:port | 62[.]238[.]117[.]133:443 | botnet_cc | 2026-08-31 | 100% |
| ip:port | 2[.]28[.]51[.]112:443 | botnet_cc | 2026-08-31 | 100% |
| ip:port | 46[.]29[.]26[.]43:443 | botnet_cc | 2026-08-31 | 100% |
| ip:port | 46[.]29[.]26[.]42:443 | botnet_cc | 2026-08-31 | 100% |
| ip:port | 103[.]13[.]210[.]168:443 | botnet_cc | 2026-08-31 | 100% |
| ip:port | 5[.]223[.]57[.]239:443 | botnet_cc | 2026-08-31 | 100% |
| ip:port | 95[.]217[.]223[.]130:443 | botnet_cc | 2026-08-31 | 100% |
| ip:port | 194[.]146[.]39[.]66:443 | botnet_cc | 2026-08-31 | 100% |
| ip:port | 178[.]104[.]215[.]65:443 | botnet_cc | 2026-08-31 | 100% |
| ip:port | 46[.]29[.]26[.]32:443 | botnet_cc | 2026-08-31 | 100% |
| ip:port | 46[.]29[.]26[.]41:443 | botnet_cc | 2026-08-31 | 100% |
| ip:port | 168[.]119[.]60[.]33:443 | botnet_cc | 2026-08-31 | 100% |
| ip:port | 5[.]78[.]91[.]236:443 | botnet_cc | 2026-08-31 | 100% |
| ip:port | 168[.]119[.]56[.]135:443 | botnet_cc | 2026-08-31 | 100% |
| ip:port | 2[.]28[.]48[.]67:443 | botnet_cc | 2026-08-31 | 100% |
// Hunt for network connections to known malicious IPs
// Source: ThreatFox - Vidar
let malicious_ips = dynamic(["95.217.223.130", "46.29.26.32", "46.29.26.35", "2.28.53.167", "5.223.57.239", "5.78.91.236", "46.29.26.42", "168.119.56.135", "91.98.236.89", "77.42.69.149", "194.146.39.66", "46.29.26.43", "62.238.126.31", "62.238.117.133", "168.119.61.136", "2.28.55.31", "2.29.15.172", "2.28.51.112", "2.28.48.67", "46.29.26.41", "46.224.87.76", "185.229.225.31", "103.13.210.168", "185.181.8.182", "178.104.215.65", "168.119.60.33"]);
CommonSecurityLog
| where DestinationIP in (malicious_ips) or SourceIP in (malicious_ips)
| project TimeGenerated, SourceIP, DestinationIP, DestinationPort, DeviceAction, Activity
| order by TimeGenerated desc
// Hunt in Defender for Endpoint network events
let malicious_ips = dynamic(["95.217.223.130", "46.29.26.32", "46.29.26.35", "2.28.53.167", "5.223.57.239", "5.78.91.236", "46.29.26.42", "168.119.56.135", "91.98.236.89", "77.42.69.149", "194.146.39.66", "46.29.26.43", "62.238.126.31", "62.238.117.133", "168.119.61.136", "2.28.55.31", "2.29.15.172", "2.28.51.112", "2.28.48.67", "46.29.26.41", "46.224.87.76", "185.229.225.31", "103.13.210.168", "185.181.8.182", "178.104.215.65", "168.119.60.33"]);
DeviceNetworkEvents
| where RemoteIP in (malicious_ips)
| project Timestamp, DeviceName, RemoteIP, RemotePort, InitiatingProcessFileName, ActionType
| order by Timestamp desc
// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - Vidar
let malicious_domains = dynamic(["rmv.sm188dvlv.icu", "vcd.sm188dvlv.icu", "tak.sm188dvlv.icu", "eos.sm188dvlv.icu", "uza.sm188dvlv.icu", "jij.sm188dvlv.icu", "x0x.sm188dvlv.icu", "hh3.sm188dvlv.icu", "jre.sm188dvlv.lat", "rrr.sm188dvlv.lat", "zca.sm188dvlv.lat", "chi.sm188dvlv.lat", "tra.sm188dvlv.lat", "nsn.sm188dvlv.lat", "jre.12naga.org", "rrr.12naga.org", "zca.12naga.org", "tra.12naga.org", "ley.sm188dvlv.icu", "sha.sm188dvlv.icu", "rsc.sm188dvlv.icu", "bnb.sm188dvlv.icu", "pnd.onlineturbo88.top", "nsn.12naga.org", "ley.123ful.net", "chi.12naga.org"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc
// Hunt for access to known malicious URLs
// Source: ThreatFox - Vidar
let malicious_urls = dynamic(["https://2.28.53.167/", "https://46.29.26.41/", "https://185.181.8.182/", "https://62.238.126.31/", "https://2.29.15.172/", "https://46.29.26.42/", "https://103.13.210.168/", "https://5.223.57.239/", "https://178.104.215.65/", "https://62.238.117.133/", "https://2.28.51.112/", "https://46.29.26.43/", "https://tra.12naga.org/", "https://chi.sm188dvlv.lat/", "https://tra.sm188dvlv.lat/", "https://nsn.sm188dvlv.lat/", "https://rrr.12naga.org/", "https://jij.sm188dvlv.icu/", "https://x0x.sm188dvlv.icu/", "https://hh3.sm188dvlv.icu/", "https://jre.sm188dvlv.lat/", "https://rrr.sm188dvlv.lat/", "https://zca.sm188dvlv.lat/", "https://bnb.sm188dvlv.icu/", "https://rmv.sm188dvlv.icu/", "https://vcd.sm188dvlv.icu/", "https://tak.sm188dvlv.icu/", "https://eos.sm188dvlv.icu/", "https://uza.sm188dvlv.icu/", "https://dev.epicgames.com/community/api/user_profiles/profile.json?hash_id=EMqJL"]);
UrlClickEvents
| where Url has_any (malicious_urls)
| project Timestamp, AccountUpn, Url, ActionType, IsClickedThrough
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DeviceNetworkEvents | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
UrlClickEvents | Ensure this data connector is enabled |
Here are specific false positive scenarios and corresponding filters for the ThreatFox: Vidar IOCs detection rule in an enterprise environment:
Scenario: Enterprise Antivirus Definition Updates
ProcessName matches known EDR update services (e.g., MsMpEng.exe, CFSvc.exe) and the CommandLine contains keywords like “update,” “download,” or specific vendor update URLs.Scenario: Scheduled Backup Jobs Accessing Shared Resources
DOMAIN\BackupSvc) during defined maintenance windows (e.g., 02:00–04:00 local time), filtering out events where the SourceIP belongs to the internal backup infrastructure subnet.Scenario: Software Deployment via Configuration Management