s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1815176 high

📛 Threat Title

Vidar: URL that delivers a malware payload https://exclusivemodelcollective.com/

Category: Vidar Published: Source updated: First seen: Last updated: Source: Threatfox IOCs/Threats

Description

Indicator that identifies a malware distribution server (payload delivery). IOC type: URL that delivers a malware payload. Attributed malware: Vidar. Confidence: 75. First seen: 2026-05-16 00:15:04 UTC. Reporter: anonymous. Tags: ClickFix, compromised, etherhiding, Polygon, Vidar, WordPress.

Indicators of Compromise (2)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

ipv4 104.237.144.228 VT 3 / 92

IOC database

Type
ipv4
Value
104.237.144.228
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Resolved from url https://exclusivemodelcollective.com/

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 3 of 92 VirusTotal vendors

VendorVerdictDetection
Abusix malicious malicious
Criminal IP malicious malicious
alphaMountain.ai suspicious not recommended

Details From VirusTotal

Basic Properties
Network104.237.128.0/19
CountryUS
AS ownerAkamai Connected Cloud
ASN63949
Regional registryARIN
History
Last analysis2026-05-15 14:17 UTC
Last modified on VirusTotal2026-05-16 02:57 UTC
WHOIS record date2026-04-18 16:42 UTC

url https://exclusivemodelcollective.com/

IOC database

Type
url
Value
https://exclusivemodelcollective.com/
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
URL that delivers a malware payload attributed to Vidar

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (2)

  • Malpedia profile Threatfox IOCs/Threats
  • ThreatFox IOC page Threatfox IOCs/Threats

    Indicator that identifies a malware distribution server (payload delivery). IOC type: URL that delivers a malware payload. Attributed malware: Vidar. Confidence: 75. First seen: 2026-05-16 00:15:04 UTC. Reporter: anonymous. Tags: ClickFix, compromised, etherhiding, Polygon, Vidar, WordPress.

Remediations (10)

  • web:cybersecuritynews.com

    Vidar focuses on pulling information that can be converted into financial gain or used to access other systems. Once the loader completes its work and the payload runs, the malware targets browser-stored credentials, saved session cookies, cryptocurrency wallet files, and general system data.

  • web:gbhackers.com

    Vidar has evolved from a basic Arkei-based credential stealer into a multi-stage, stealth-focused infostealer that now hides second‑stage payloads within JPEG and TXT files to evade modern defenses. First observed in 2018, Vidar now operates as a mature Malware‑as‑a‑Service (MaaS) with flexible delivery, multi‑stage execution, and strong data‑theft capabilities. Attackers weaponize ...

  • web:seceon.com

    Malware authors are increasingly using multi-stage delivery techniques to evade detection, blending malicious payloads into seemingly harmless file formats. New reporting from Cybersecurity News reveals that Vidar is delivering its payload through JPEG and TXT files while leveraging scripting, obfuscation, and in-memory execution to remain undetected. The campaign combines multiple evasion ...

  • web:securitylabs.datadoghq.com

    The packages masquerade as benign SDKs and provide legitimate functionality but nevertheless execute Vidar infostealer malware on the victim system To the best of our knowledge, this is the first public disclosure of Vidar malware being delivered via npm packages We attribute this campaign to a threat activity cluster that we track as MUT-4831

  • web:socprime.com

    The researchers also described how WScript, PowerShell, and RegAsm.exe were abused as execution proxies, enabling the malware to decode and launch a hidden DLL entirely in memory. Network traffic further confirmed HTTP -based retrieval of staged JPEG and TXT payloads from a hard-coded IP address. Mitigation

  • web:threatfox.abuse.ch

    Anonymous Compromised WordPress site distributing Vidar Stealer via Polygon ClickFix campaign.

  • web:www.huntress.com

    Vidar malware is an information-stealing trojan that targets sensitive data, such as login credentials and cryptocurrency wallets. It works by deploying a payload to infected systems, collecting data, and transmitting it to command and control servers controlled by attackers.

  • web:www.levelblue.com

    The script processed an external payload file and subsequently initiated network communication. Further analysis confirmed communication with infrastructure associated with Vidar , a well-known information-stealing malware capable of harvesting credentials, browser data, cryptocurrency wallets, and system information.

  • web:www.malwarebytes.com

    Malware loaders (also known as droppers or downloaders) are common tools in the cybercrime ecosystem. Their main job is to stealthily compromise a system and then deliver one or more additional malware payloads . In this campaign, the loader ultimately decrypts and executes the Vidar infostealer.

  • web:www.pointwild.com

    Initial Infection Vector for Vidar (2026) The initial infection vector for Vidar infostealer in 2026 has significantly evolved from traditional exploit-based delivery to highly user-driven and social engineering-based execution chains.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

VirusTotal Information

loading…

IP Geolocation

Loading…