s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1812106 high

📛 Threat Title

Vidar: Domain that is used for botnet Command&control (C&C) fke.chriskendallvo.com

Category: Vidar Published: Source updated: First seen: Last updated: Source: Threatfox IOCs/Threats

Description

Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Vidar. Confidence: 100. First seen: 2026-05-14 07:30:12 UTC. Reporter: crep1x. Tags: Vidar.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain fke.chriskendallvo.com UrlVoid 5 / 35

IOC database

Type
domain
Value
fke.chriskendallvo.com
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Domain that is used for botnet Command&control (C&C) attributed to Vidar

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (2)

  • Malpedia profile Threatfox IOCs/Threats
  • ThreatFox IOC page Threatfox IOCs/Threats

    Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Vidar. Confidence: 100. First seen: 2026-05-14 07:30:12 UTC. Reporter: crep1x. Tags: Vidar.

Remediations (10)

  • web:acsmi.org

    A botnet's command and control (C2) structure dictates its efficiency and resilience. Centralized models use singular C2 servers that broadcast commands to infected nodes, offering simplicity but with a critical vulnerability—once identified, authorities can dismantle them.

  • web:docs.fortinet.com

    From your internal network PC, use a command line tool, such as dig or nslookup, to query this domain and verify that it is blocked by the DNS filter botnet C&C .

  • web:exchange.xforce.ibmcloud.com

    IBM X-Force Exchange is a threat intelligence sharing platform enabling research on security threats, aggregation of intelligence, and collaboration with peers

  • web:thehackernews.com

    Vidar stealer now uses throwaway accounts on social media platforms to retrieve the address of its command-and-control servers and steal information.

  • web:thehackernews.com

    A key domain used by the Vidar actors is my-odin [.]com, which serves as the one-stop destination to manage the panel, authenticate affiliates, and share files. While previously it was possible to download files from the site without any authentication, performing the same action now redirects the user to a login page.

  • web:usa.kaspersky.com

    The Vidar stealer is a technical malware used to infect devices and steal information. Here's how it works and how to take preventative measures.

  • web:www.censys.com

    Vidar Operational Details Vidar uses common network communication methods, and once in place, it will connect to a Telegram server to fetch the URL of the Command and Control (C2) server. In the following two screenshots, you will see examples of this C2 distribution method via Telegram or, if that fails, a backup Steam account.

  • web:www.checkpoint.com

    Vidar is an infostealer malware that can also be used to deliver additional forms of malware. Some of the ways that an organization can protect against this malware threat include the following: Employee Training: Vidar is commonly distributed via phishing emails or fake downloads of legitimate software, which actually deliver the malware.

  • web:www.crowdstrike.com

    What are command and control attacks? C&C (also known as C2) is a method that cybercriminals use to communicate with compromised devices within a target company's network. In a C&C attack, an attacker uses a server to send commands to — and receive data from — computers compromised by malware. This server is also known as a C2 or C&C server.

  • web:www.cyfirma.com

    Additionally, it examines their utilization of social media platforms to procure command and control details for data exfiltration and updates. Introduction This study provides a concise overview of Vidar Stealer, a potent malware written in C++, capable of stealing a wide range of data from the compromised system.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.