s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1811992 high

📛 Threat Title

Vidar: Domain that is used for botnet Command&control (C&C) mme.chriskendallvo.com

Category: Vidar Published: Source updated: First seen: Last updated: Source: Threatfox IOCs/Threats

Description

Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Vidar. Confidence: 100. First seen: 2026-05-13 21:00:12 UTC. Reporter: crep1x. Tags: Vidar.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain mme.chriskendallvo.com VT 15 / 91 UrlVoid 5 / 35 1 feed

IOC database

Type
domain
Value
mme.chriskendallvo.com
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Domain that is used for botnet Command&control (C&C) attributed to Vidar

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Flagged by 15 of 91 VirusTotal vendors

VendorVerdictDetection
ADMINUSLabs malicious malicious
alphaMountain.ai malicious malicious
AlphaSOC malicious malware
BitDefender malicious phishing
CRDF malicious malicious
Dr.Web malicious malicious
Fortinet malicious malware
G-Data malicious phishing
Kaspersky malicious malware
Lionic malicious malicious
MalwareURL malicious malware
Sophos malicious malicious
VIPRE malicious malware
Certego suspicious suspicious
SOCRadar suspicious suspicious

Details From VirusTotal

Basic Properties
RegistrarENOM, INC.
TLDcom
History
Creation date2016-10-14 23:05 UTC
Last analysis2026-05-29 08:54 UTC
Last modified on VirusTotal2026-05-29 10:07 UTC
Last WHOIS update2026-05-13 20:54 UTC

References (2)

  • Malpedia profile Threatfox IOCs/Threats
  • ThreatFox IOC page Threatfox IOCs/Threats

    Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Vidar. Confidence: 100. First seen: 2026-05-13 21:00:12 UTC. Reporter: crep1x. Tags: Vidar.

Remediations (10)

  • web:101.school

    Command and Control (C&C) servers play a crucial role in the operation of botnets and other forms of malware. They serve as the central hub from which cybercriminals can control infected machines, known as 'bots'.

  • web:acsmi.org

    A botnet's command and control (C2) structure dictates its efficiency and resilience. Centralized models use singular C2 servers that broadcast commands to infected nodes, offering simplicity but with a critical vulnerability—once identified, authorities can dismantle them.

  • web:blogs.cisco.com

    A command-and-control (also referred to as C&C or C2) server is an endpoint compromised and controlled by an attacker. Devices on your network can be commandeered by a cybercriminal to become a command center or a botnet (a term coined by a combination of the words "ro bot" and " net work") with the intention of obtaining full network ...

  • web:docs.fortinet.com

    From your internal network PC, use a command line tool, such as dig or nslookup, to query this domain and verify that it is blocked by the DNS filter botnet C&C .

  • web:eln0ty.github.io

    Deep Analysis of Vidar Information Stealer 17 minute read On this page Vidar overview Sample Preparation (strings & dlls) Decrypt strings Building imports C2 Server How to understand the configuration format Folder generation Browsers 2 Factor Authentication software (2FA) Messengers Crypto Wallets Information log Result Other payloads Kill Task Exfiltration Conclusion Yara Rules Vidar (forked ...

  • web:exchange.xforce.ibmcloud.com

    IBM X-Force Exchange is a threat intelligence sharing platform enabling research on security threats, aggregation of intelligence, and collaboration with peers

  • web:thehackernews.com

    A key domain used by the Vidar actors is my-odin [.]com, which serves as the one-stop destination to manage the panel, authenticate affiliates, and share files. While previously it was possible to download files from the site without any authentication, performing the same action now redirects the user to a login page.

  • web:www.censys.com

    Vidar Operational Details Vidar uses common network communication methods, and once in place, it will connect to a Telegram server to fetch the URL of the Command and Control (C2) server. In the following two screenshots, you will see examples of this C2 distribution method via Telegram or, if that fails, a backup Steam account.

  • web:www.checkpoint.com

    Vidar is an infostealer malware that can also be used to deliver additional forms of malware. Some of the ways that an organization can protect against this malware threat include the following: Employee Training: Vidar is commonly distributed via phishing emails or fake downloads of legitimate software, which actually deliver the malware.

  • web:www.crowdstrike.com

    What are command and control attacks? C&C (also known as C2) is a method that cybercriminals use to communicate with compromised devices within a target company's network. In a C&C attack, an attacker uses a server to send commands to — and receive data from — computers compromised by malware. This server is also known as a C2 or C&C server.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.