This hunt hypothesis targets adversaries utilizing Vidar malware to exfiltrate credentials and sensitive data through initial phishing vectors, enabling subsequent lateral movement and long-term persistence within the network. The SOC team should proactively hunt for these indicators in Azure Sentinel to detect early-stage infections that could lead to significant data breaches before the threat establishes deep-rooted access.
Malware Family: Vidar Total IOCs: 36 IOC Types: md5_hash, sha256_hash, sha1_hash
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| sha256_hash | 40b643468356c0fd751893647ad0dc9e2a0019427e4f5f0e2f6e559efcecb977 | payload | 2026-09-02 | 95% |
| sha1_hash | a7b0d89d2f4f846e38ce3c4ea904d16113fda9ea | payload | 2026-09-02 | 95% |
| md5_hash | b135d924f409aeb7be55feacd68e946f | payload | 2026-09-02 | 95% |
| sha256_hash | 65be921e09dc27a0e34a9ce31ad9cbb99854a4d7b4be828e158b19ac849332d0 | payload | 2026-09-02 | 95% |
| sha1_hash | b9d338eeaaef4ad7ba2ca7d759ec97928d5de04a | payload | 2026-09-02 | 95% |
| md5_hash | 07ec1d0d4f4b2029430ba43303cfde85 | payload | 2026-09-02 | 95% |
| sha1_hash | 8026788ad7f9ea95083c3e8610b173bf6559f87f | payload | 2026-09-02 | 95% |
| md5_hash | cbfdc0774c54d016bf35923d3c5603ae | payload | 2026-09-02 | 95% |
| md5_hash | 6553bac9717b08d09db81cf9d47361e8 | payload | 2026-09-02 | 95% |
| sha256_hash | 921ae4b0d4344348a744504a68a434bf82e941a3575172be4bf6f929c08b89c6 | payload | 2026-09-02 | 95% |
| sha256_hash | 57f406023f5ac9e575c7c9e7befd31c42cd0699904a38cbd612b7cf72dcabf11 | payload | 2026-09-02 | 95% |
| sha1_hash | 3c0c6f56c903c2714d10754b46d5a73a8947e146 | payload | 2026-09-02 | 95% |
| sha1_hash | 5b84234672c3f2219f8c6c1124cc9e7240eb3b55 | payload | 2026-09-02 | 95% |
| md5_hash | ef77cbff6f7e2157c38d27fea5b927ac | payload | 2026-09-02 | 95% |
| sha256_hash | 3d10f5aa66dbf90ab7b1f3736bd9b3f3bf52b4b241a3eb67ba8a0c35d53f2fac | payload | 2026-09-02 | 95% |
| md5_hash | 17a06d209a2d60a1dbe2e71f3693548d | payload | 2026-09-02 | 95% |
| sha256_hash | f609e8d69684846032e7ae713b428e450556330ca65894bb3a0eaf49758f66ac | payload | 2026-09-02 | 95% |
| sha1_hash | ec53bc860173a0937929e70d994a8bcbb6ce8954 | payload | 2026-09-02 | 95% |
| md5_hash | cea0892394ac5e26c48336c1b89629ed | payload | 2026-09-02 | 95% |
| md5_hash | 981ab1ef2193514f56e37e8ed322837e | payload | 2026-09-02 | 95% |
| sha256_hash | 1dd8bce285a289682e1a21e9e81d9254f091c21bc189682f4afdb82a666bba39 | payload | 2026-09-02 | 95% |
| sha1_hash | 6dc72501038e40c90aca22445f827916e4b0e536 | payload | 2026-09-02 | 95% |
| sha256_hash | 7c83eaa84cbf4f5bcde0d3d7c636b817e710fc33dbe0ba69f912f906bf93bb9f | payload | 2026-09-02 | 95% |
| sha1_hash | b23111ec2f200f9797ae7130a323e70685a24885 | payload | 2026-09-02 | 95% |
| sha1_hash | a12c6aaccc3dcb8a22ba3bfe5d19f49417ce5136 | payload | 2026-09-02 | 95% |
// Hunt for files matching known malicious hashes
// Source: ThreatFox - Vidar
let malicious_hashes = dynamic(["40b643468356c0fd751893647ad0dc9e2a0019427e4f5f0e2f6e559efcecb977", "a7b0d89d2f4f846e38ce3c4ea904d16113fda9ea", "b135d924f409aeb7be55feacd68e946f", "65be921e09dc27a0e34a9ce31ad9cbb99854a4d7b4be828e158b19ac849332d0", "b9d338eeaaef4ad7ba2ca7d759ec97928d5de04a", "07ec1d0d4f4b2029430ba43303cfde85", "8026788ad7f9ea95083c3e8610b173bf6559f87f", "cbfdc0774c54d016bf35923d3c5603ae", "6553bac9717b08d09db81cf9d47361e8", "921ae4b0d4344348a744504a68a434bf82e941a3575172be4bf6f929c08b89c6", "57f406023f5ac9e575c7c9e7befd31c42cd0699904a38cbd612b7cf72dcabf11", "3c0c6f56c903c2714d10754b46d5a73a8947e146", "5b84234672c3f2219f8c6c1124cc9e7240eb3b55", "ef77cbff6f7e2157c38d27fea5b927ac", "3d10f5aa66dbf90ab7b1f3736bd9b3f3bf52b4b241a3eb67ba8a0c35d53f2fac", "17a06d209a2d60a1dbe2e71f3693548d", "f609e8d69684846032e7ae713b428e450556330ca65894bb3a0eaf49758f66ac", "ec53bc860173a0937929e70d994a8bcbb6ce8954", "cea0892394ac5e26c48336c1b89629ed", "981ab1ef2193514f56e37e8ed322837e", "1dd8bce285a289682e1a21e9e81d9254f091c21bc189682f4afdb82a666bba39", "6dc72501038e40c90aca22445f827916e4b0e536", "7c83eaa84cbf4f5bcde0d3d7c636b817e710fc33dbe0ba69f912f906bf93bb9f", "b23111ec2f200f9797ae7130a323e70685a24885", "a12c6aaccc3dcb8a22ba3bfe5d19f49417ce5136", "389055b0def3f57fc15695e1e7623534", "98ec6a83a313319730bd143f6ce63ddce4389f638ad598c630faeac804755555", "c57391593bb9d975cd014089eca9cf38", "c84ac5fef6a85788d318a2c102695628", "2c786f7009cc5e1fba5471a88b23b34dce6e1578ee9f664ec62bf48227ba384b", "2dd409f171e9de0eb9c531a63236939a6ec91e21", "abcdf531d86451ab05ab7faf02a85f7c987a3069401110726f52de0d38532530", "f3dd558bf910098207f1e65fb8df17662433a8ad", "d86cb6fcca1b22095d00707c35c22ca7bb721063d8a38e820b7393f3998062c9", "edeeae623480d4be1c15b8ddeedcf15bf25a8b71", "b474726d5d410a8edf0e4b9374ac609d"]);
DeviceFileEvents
| where SHA256 in (malicious_hashes) or SHA1 in (malicious_hashes) or MD5 in (malicious_hashes)
| project Timestamp, DeviceName, FileName, FolderPath, SHA256, InitiatingProcessFileName
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
DeviceFileEvents | Ensure this data connector is enabled |
Here are 5 specific false positive scenarios for the ThreatFox: Vidar IOCs detection rule, including context and recommended filters/exclusions:
Enterprise Antivirus Real-Time Scanning of Archived Attachments
Microsoft.Exchange.Transport service account and filter out events where the source path is within the \Archive\Legal\Templates\ directory. Add a condition to ignore alerts if the file age exceeds 30 days, as Vidar typically targets fresh phishing attachments.Scheduled Credential Backup Jobs via PowerShell
Backup-Credentials.ps1) that extracts Active Directory user credentials and exports them to an encrypted CSV for compliance auditing. This process involves reading credential stores and writing to network shares, which mimics Vidar’s behavior of stealing credentials and exfiltrating data via lateral movement scripts.TASK-04X-CRED-BACKUP) and the associated service account (svc-compliance-backup). Exclude alerts where the parent process is powershell.exe running with the -ExecutionPolicy Bypass flag during the defined maintenance window (02:00–04:00 UTC).Third-Party RMM Agent Health Checks