← Back to SOC feed Coverage →

ThreatFox: Vidar IOCs

ioc-hunt HIGH ThreatFox
DnsEventsUrlClickEvents
iocthreatfoxwin-vidar
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at ThreatFox →
Retrieved: 2026-07-17T11:00:00Z · Confidence: high

Hunt Hypothesis

This hunt targets adversary behavior where Vidar malware establishes encrypted command-and-control channels to stealthily exfiltrate stolen credentials and sensitive data from endpoints. Proactively hunting for these specific IOCs in Azure Sentinel is critical because early detection of this high-severity threat prevents lateral movement and mitigates the risk of widespread identity compromise before data leaves the network.

IOC Summary

Malware Family: Vidar Total IOCs: 16 IOC Types: domain, url

TypeValueThreat TypeFirst SeenConfidence
urlhxxps://d11.kliksm188.top/botnet_cc2026-07-17100%
urlhxxps://d11.ambiltogel.net/botnet_cc2026-07-17100%
domaind11.kliksm188.topbotnet_cc2026-07-17100%
domaind11.ambiltogel.netbotnet_cc2026-07-17100%
urlhxxps://bfg.kliksm188.top/botnet_cc2026-07-17100%
domainbfg.kliksm188.topbotnet_cc2026-07-17100%
domainbfg.ambiltogel.netbotnet_cc2026-07-17100%
urlhxxps://bfg.ambiltogel.net/botnet_cc2026-07-17100%
urlhxxps://ffz.kliksm188.top/botnet_cc2026-07-1675%
domainffz.kliksm188.topbotnet_cc2026-07-1675%
urlhxxps://ffz.ambiltogel.net/botnet_cc2026-07-16100%
domainffz.ambiltogel.netbotnet_cc2026-07-16100%
domaincra.kliksm188.topbotnet_cc2026-07-1675%
urlhxxps://cra.kliksm188.top/botnet_cc2026-07-1675%
urlhxxps://cra.ambiltogel.net/botnet_cc2026-07-16100%
domaincra.ambiltogel.netbotnet_cc2026-07-16100%

KQL: Domain Hunt

// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - Vidar
let malicious_domains = dynamic(["d11.kliksm188.top", "d11.ambiltogel.net", "bfg.kliksm188.top", "bfg.ambiltogel.net", "ffz.kliksm188.top", "ffz.ambiltogel.net", "cra.kliksm188.top", "cra.ambiltogel.net"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc

KQL: Url Hunt

// Hunt for access to known malicious URLs
// Source: ThreatFox - Vidar
let malicious_urls = dynamic(["https://d11.kliksm188.top/", "https://d11.ambiltogel.net/", "https://bfg.kliksm188.top/", "https://bfg.ambiltogel.net/", "https://ffz.kliksm188.top/", "https://ffz.ambiltogel.net/", "https://cra.kliksm188.top/", "https://cra.ambiltogel.net/"]);
UrlClickEvents
| where Url has_any (malicious_urls)
| project Timestamp, AccountUpn, Url, ActionType, IsClickedThrough
| order by Timestamp desc

Required Data Sources

Sentinel TableNotes
DnsEventsEnsure this data connector is enabled
UrlClickEventsEnsure this data connector is enabled

References

False Positive Guidance

Here are 5 specific false positive scenarios for the ThreatFox: Vidar IOCs detection rule in an enterprise environment, along with suggested filters or exclusions:


Original source: https://threatfox.abuse.ch/browse/malware/win.vidar/