TF-1815176
high
📛 Threat Title
Vidar: URL that delivers a malware payload https://exclusivemodelcollective.com/
Description
Indicator that identifies a malware distribution server (payload delivery). IOC type: URL that delivers a malware payload. Attributed malware: Vidar. Confidence: 75. First seen: 2026-05-16 00:15:04 UTC. Reporter: anonymous. Tags: ClickFix, compromised, etherhiding, Polygon, Vidar, WordPress.
Indicators of Compromise (2)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
104.237.144.228
VT 3 / 92
IOC database
- Type
- ipv4
- Value
104.237.144.228- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Resolved from url https://exclusivemodelcollective.com/
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 3 of 92 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Abusix | malicious | malicious |
| Criminal IP | malicious | malicious |
| alphaMountain.ai | suspicious | not recommended |
Details From VirusTotal
Basic Properties
| Network | 104.237.128.0/19 |
| Country | US |
| AS owner | Akamai Connected Cloud |
| ASN | 63949 |
| Regional registry | ARIN |
History
| Last analysis | 2026-05-15 14:17 UTC |
| Last modified on VirusTotal | 2026-05-16 02:57 UTC |
| WHOIS record date | 2026-04-18 16:42 UTC |
url
https://exclusivemodelcollective.com/
IOC database
- Type
- url
- Value
https://exclusivemodelcollective.com/- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- URL that delivers a malware payload attributed to Vidar
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
- Malpedia profile Threatfox IOCs/Threats
-
ThreatFox IOC page
Threatfox IOCs/Threats
Indicator that identifies a malware distribution server (payload delivery). IOC type: URL that delivers a malware payload. Attributed malware: Vidar. Confidence: 75. First seen: 2026-05-16 00:15:04 UTC. Reporter: anonymous. Tags: ClickFix, compromised, etherhiding, Polygon, Vidar, WordPress.
Remediations (10)
-
web:cybersecuritynews.com
Vidar focuses on pulling information that can be converted into financial gain or used to access other systems. Once the loader completes its work and the payload runs, the malware targets browser-stored credentials, saved session cookies, cryptocurrency wallet files, and general system data.
-
web:gbhackers.com
Vidar has evolved from a basic Arkei-based credential stealer into a multi-stage, stealth-focused infostealer that now hides second‑stage payloads within JPEG and TXT files to evade modern defenses. First observed in 2018, Vidar now operates as a mature Malware‑as‑a‑Service (MaaS) with flexible delivery, multi‑stage execution, and strong data‑theft capabilities. Attackers weaponize ...
-
web:seceon.com
Malware authors are increasingly using multi-stage delivery techniques to evade detection, blending malicious payloads into seemingly harmless file formats. New reporting from Cybersecurity News reveals that Vidar is delivering its payload through JPEG and TXT files while leveraging scripting, obfuscation, and in-memory execution to remain undetected. The campaign combines multiple evasion ...
-
web:securitylabs.datadoghq.com
The packages masquerade as benign SDKs and provide legitimate functionality but nevertheless execute Vidar infostealer malware on the victim system To the best of our knowledge, this is the first public disclosure of Vidar malware being delivered via npm packages We attribute this campaign to a threat activity cluster that we track as MUT-4831
-
web:socprime.com
The researchers also described how WScript, PowerShell, and RegAsm.exe were abused as execution proxies, enabling the malware to decode and launch a hidden DLL entirely in memory. Network traffic further confirmed HTTP -based retrieval of staged JPEG and TXT payloads from a hard-coded IP address. Mitigation
-
web:threatfox.abuse.ch
Anonymous Compromised WordPress site distributing Vidar Stealer via Polygon ClickFix campaign.
-
web:www.huntress.com
Vidar malware is an information-stealing trojan that targets sensitive data, such as login credentials and cryptocurrency wallets. It works by deploying a payload to infected systems, collecting data, and transmitting it to command and control servers controlled by attackers.
-
web:www.levelblue.com
The script processed an external payload file and subsequently initiated network communication. Further analysis confirmed communication with infrastructure associated with Vidar , a well-known information-stealing malware capable of harvesting credentials, browser data, cryptocurrency wallets, and system information.
-
web:www.malwarebytes.com
Malware loaders (also known as droppers or downloaders) are common tools in the cybercrime ecosystem. Their main job is to stealthily compromise a system and then deliver one or more additional malware payloads . In this campaign, the loader ultimately decrypts and executes the Vidar infostealer.
-
web:www.pointwild.com
Initial Infection Vector for Vidar (2026) The initial infection vector for Vidar infostealer in 2026 has significantly evolved from traditional exploit-based delivery to highly user-driven and social engineering-based execution chains.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.