TF-1811992
high
📛 Threat Title
Vidar: Domain that is used for botnet Command&control (C&C) mme.chriskendallvo.com
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Vidar. Confidence: 100. First seen: 2026-05-13 21:00:12 UTC. Reporter: crep1x. Tags: Vidar.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
mme.chriskendallvo.com
VT 15 / 91
UrlVoid 5 / 35
1 feed
IOC database
- Type
- domain
- Value
mme.chriskendallvo.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Domain that is used for botnet Command&control (C&C) attributed to Vidar
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Flagged by 15 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ADMINUSLabs | malicious | malicious |
| alphaMountain.ai | malicious | malicious |
| AlphaSOC | malicious | malware |
| BitDefender | malicious | phishing |
| CRDF | malicious | malicious |
| Dr.Web | malicious | malicious |
| Fortinet | malicious | malware |
| G-Data | malicious | phishing |
| Kaspersky | malicious | malware |
| Lionic | malicious | malicious |
| MalwareURL | malicious | malware |
| Sophos | malicious | malicious |
| VIPRE | malicious | malware |
| Certego | suspicious | suspicious |
| SOCRadar | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Registrar | ENOM, INC. |
| TLD | com |
History
| Creation date | 2016-10-14 23:05 UTC |
| Last analysis | 2026-05-29 08:54 UTC |
| Last modified on VirusTotal | 2026-05-29 10:07 UTC |
| Last WHOIS update | 2026-05-13 20:54 UTC |
References (2)
- Malpedia profile Threatfox IOCs/Threats
-
ThreatFox IOC page
Threatfox IOCs/Threats
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Vidar. Confidence: 100. First seen: 2026-05-13 21:00:12 UTC. Reporter: crep1x. Tags: Vidar.
Remediations (10)
-
web:101.school
Command and Control (C&C) servers play a crucial role in the operation of botnets and other forms of malware. They serve as the central hub from which cybercriminals can control infected machines, known as 'bots'.
-
web:acsmi.org
A botnet's command and control (C2) structure dictates its efficiency and resilience. Centralized models use singular C2 servers that broadcast commands to infected nodes, offering simplicity but with a critical vulnerability—once identified, authorities can dismantle them.
-
web:blogs.cisco.com
A command-and-control (also referred to as C&C or C2) server is an endpoint compromised and controlled by an attacker. Devices on your network can be commandeered by a cybercriminal to become a command center or a botnet (a term coined by a combination of the words "ro bot" and " net work") with the intention of obtaining full network ...
-
web:docs.fortinet.com
From your internal network PC, use a command line tool, such as dig or nslookup, to query this domain and verify that it is blocked by the DNS filter botnet C&C .
-
web:eln0ty.github.io
Deep Analysis of Vidar Information Stealer 17 minute read On this page Vidar overview Sample Preparation (strings & dlls) Decrypt strings Building imports C2 Server How to understand the configuration format Folder generation Browsers 2 Factor Authentication software (2FA) Messengers Crypto Wallets Information log Result Other payloads Kill Task Exfiltration Conclusion Yara Rules Vidar (forked ...
-
web:exchange.xforce.ibmcloud.com
IBM X-Force Exchange is a threat intelligence sharing platform enabling research on security threats, aggregation of intelligence, and collaboration with peers
-
web:thehackernews.com
A key domain used by the Vidar actors is my-odin [.]com, which serves as the one-stop destination to manage the panel, authenticate affiliates, and share files. While previously it was possible to download files from the site without any authentication, performing the same action now redirects the user to a login page.
-
web:www.censys.com
Vidar Operational Details Vidar uses common network communication methods, and once in place, it will connect to a Telegram server to fetch the URL of the Command and Control (C2) server. In the following two screenshots, you will see examples of this C2 distribution method via Telegram or, if that fails, a backup Steam account.
-
web:www.checkpoint.com
Vidar is an infostealer malware that can also be used to deliver additional forms of malware. Some of the ways that an organization can protect against this malware threat include the following: Employee Training: Vidar is commonly distributed via phishing emails or fake downloads of legitimate software, which actually deliver the malware.
-
web:www.crowdstrike.com
What are command and control attacks? C&C (also known as C2) is a method that cybercriminals use to communicate with compromised devices within a target company's network. In a C&C attack, an attacker uses a server to send commands to — and receive data from — computers compromised by malware. This server is also known as a C2 or C&C server.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.