This hunt detects adversary activity involving the Vidar infostealer by monitoring for matches against its known indicators of compromise (IOCs) within Azure Sentinel logs. Proactively hunting for these specific IOCs is critical to identify early-stage infections and prevent data exfiltration before the malware establishes persistence or spreads laterally across the network.
Malware Family: Vidar Total IOCs: 114 IOC Types: url, domain, ip:port
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| ip:port | 62[.]238[.]55[.]102:443 | botnet_cc | 2026-08-03 | 100% |
| ip:port | 65[.]108[.]82[.]108:443 | botnet_cc | 2026-08-03 | 100% |
| ip:port | 157[.]180[.]35[.]166:443 | botnet_cc | 2026-08-03 | 100% |
| ip:port | 2[.]28[.]15[.]55:443 | botnet_cc | 2026-08-03 | 100% |
| ip:port | 65[.]108[.]201[.]76:443 | botnet_cc | 2026-08-03 | 100% |
| ip:port | 176[.]9[.]118[.]53:443 | botnet_cc | 2026-08-03 | 100% |
| ip:port | 37[.]27[.]197[.]184:443 | botnet_cc | 2026-08-03 | 100% |
| ip:port | 37[.]27[.]194[.]103:443 | botnet_cc | 2026-08-03 | 100% |
| ip:port | 167[.]233[.]215[.]136:443 | botnet_cc | 2026-08-03 | 100% |
| ip:port | 159[.]69[.]103[.]239:443 | botnet_cc | 2026-08-03 | 100% |
| ip:port | 65[.]108[.]71[.]75:443 | botnet_cc | 2026-08-03 | 100% |
| ip:port | 5[.]75[.]238[.]232:443 | botnet_cc | 2026-08-03 | 100% |
| ip:port | 65[.]109[.]173[.]132:443 | botnet_cc | 2026-08-03 | 100% |
| ip:port | 2[.]28[.]12[.]152:443 | botnet_cc | 2026-08-03 | 100% |
| ip:port | 2[.]28[.]13[.]53:443 | botnet_cc | 2026-08-03 | 100% |
| ip:port | 37[.]27[.]193[.]182:443 | botnet_cc | 2026-08-03 | 100% |
| ip:port | 37[.]27[.]204[.]215:443 | botnet_cc | 2026-08-03 | 100% |
| ip:port | 2[.]28[.]9[.]232:443 | botnet_cc | 2026-08-03 | 100% |
| ip:port | 65[.]109[.]165[.]156:443 | botnet_cc | 2026-08-03 | 100% |
| ip:port | 178[.]105[.]99[.]239:443 | botnet_cc | 2026-08-03 | 100% |
| ip:port | 77[.]42[.]79[.]241:443 | botnet_cc | 2026-08-03 | 100% |
| ip:port | 46[.]225[.]62[.]20:443 | botnet_cc | 2026-08-03 | 100% |
| ip:port | 2[.]28[.]9[.]155:443 | botnet_cc | 2026-08-03 | 100% |
| ip:port | 88[.]99[.]126[.]229:443 | botnet_cc | 2026-08-03 | 100% |
| ip:port | 77[.]42[.]49[.]112:443 | botnet_cc | 2026-08-03 | 100% |
// Hunt for network connections to known malicious IPs
// Source: ThreatFox - Vidar
let malicious_ips = dynamic(["77.42.49.112", "65.108.71.75", "2.28.9.232", "2.28.13.53", "65.108.141.220", "2.28.15.55", "2.28.12.152", "65.108.1.249", "138.201.157.90", "5.75.238.232", "46.225.62.20", "167.233.215.136", "65.109.173.132", "2.28.9.155", "157.180.35.166", "65.108.82.108", "62.238.55.102", "176.9.118.53", "65.109.165.156", "178.105.99.239", "37.27.194.103", "37.27.197.184", "37.27.204.215", "65.108.65.198", "88.99.126.229", "65.108.201.76", "65.108.197.205", "159.69.103.239", "37.27.193.182", "77.42.79.241"]);
CommonSecurityLog
| where DestinationIP in (malicious_ips) or SourceIP in (malicious_ips)
| project TimeGenerated, SourceIP, DestinationIP, DestinationPort, DeviceAction, Activity
| order by TimeGenerated desc
// Hunt in Defender for Endpoint network events
let malicious_ips = dynamic(["77.42.49.112", "65.108.71.75", "2.28.9.232", "2.28.13.53", "65.108.141.220", "2.28.15.55", "2.28.12.152", "65.108.1.249", "138.201.157.90", "5.75.238.232", "46.225.62.20", "167.233.215.136", "65.109.173.132", "2.28.9.155", "157.180.35.166", "65.108.82.108", "62.238.55.102", "176.9.118.53", "65.109.165.156", "178.105.99.239", "37.27.194.103", "37.27.197.184", "37.27.204.215", "65.108.65.198", "88.99.126.229", "65.108.201.76", "65.108.197.205", "159.69.103.239", "37.27.193.182", "77.42.79.241"]);
DeviceNetworkEvents
| where RemoteIP in (malicious_ips)
| project Timestamp, DeviceName, RemoteIP, RemotePort, InitiatingProcessFileName, ActionType
| order by Timestamp desc
// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - Vidar
let malicious_domains = dynamic(["crm.808skor.org", "pos.808skor.org", "pnd.808skor.org", "vho.808skor.org", "xip.808skor.org", "vog.peluangsm188.top", "dbm.peluangsm188.top", "m36.peluangsm188.top", "out.peluangsm188.top", "bpo.peluangsm188.top", "bpo.pelorsm188.top", "tyb.pelorsm188.top", "sro.pelorsm188.top", "ggr.pelorsm188.top", "cto.pelorsm188.top", "bpo.akasia988.net", "dnz.cau777.org", "dnz.popi999.net", "out.popi999.net", "pey.cau777.org", "pey.popi999.net", "rrn.cau777.org", "rrn.popi999.net", "vog.cau777.org", "vog.popi999.net"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc
// Hunt for access to known malicious URLs
// Source: ThreatFox - Vidar
let malicious_urls = dynamic(["https://2.28.15.55/", "https://65.108.201.76/", "https://116.202.186.230/", "https://176.9.118.53/", "https://62.238.55.102/", "https://159.69.103.239/", "https://65.108.71.75/", "https://5.75.238.232/", "https://65.108.82.108/", "https://157.180.35.166/", "https://2.28.13.53/", "https://37.27.193.182/", "https://37.27.204.215/", "https://37.27.197.184/", "https://37.27.194.103/", "https://167.233.215.136/", "https://77.42.79.241/", "https://46.225.62.20/", "https://2.28.9.155/", "https://65.109.173.132/", "https://2.28.12.152/", "https://65.108.197.205/", "https://2.28.9.232/", "https://65.109.165.156/", "https://178.105.99.239/", "https://65.108.1.249/", "https://88.99.126.229/", "https://77.42.49.112/", "https://65.108.141.220/", "https://65.108.65.198/"]);
UrlClickEvents
| where Url has_any (malicious_urls)
| project Timestamp, AccountUpn, Url, ActionType, IsClickedThrough
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DeviceNetworkEvents | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
UrlClickEvents | Ensure this data connector is enabled |
Here are specific false positive scenarios and corresponding filters/exclusions for the ThreatFox: Vidar IOCs detection rule in an enterprise environment:
Scenario: Scheduled Antivirus or EDR Definition Updates
MsMpEng.exe, FalconSensorService.exe) and restrict the alert to only trigger when these processes are running under the SYSTEM account context during standard maintenance windows.Scenario: Deployment of Internal Patch Management Jobs
DOMAIN\SCCM-Deploy-Svc) and limit detection to the execution time window defined in the scheduled task (e.g., 02:00 – 04:00 AM local time).Scenario: Execution of Third-Party Backup or Monitoring Agents