TF-1932737
high
📛 Threat Title
Vidar: Domain that is used for botnet Command&control (C&C) hj.1jp88.org
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Vidar. Confidence: 100. First seen: 2026-09-25 08:35:45 UTC. Last seen: 2026-09-25 09:23:15 UTC. Reporter: crep1x. Tags: Vidar.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
hj.1jp88.org
VT 8 / 91
UrlVoid 3 / 36
IOC database
- Type
- domain
- Value
hj.1jp88.org- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Ingested from IOC source: https://threatfox.abuse.ch/downloads/hostfile/
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 8 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alphaMountain.ai | malicious | malicious |
| ESET | malicious | malware |
| Fortinet | malicious | malware |
| Lionic | malicious | malicious |
| Lumu | malicious | malware |
| MalwareURL | malicious | malware |
| SOCRadar | malicious | malicious |
| Sophos | malicious | malicious |
Details From VirusTotal
Basic Properties
| TLD | org |
History
| Creation date | 2025-11-28 00:00 UTC |
| Last analysis | 2026-09-26 01:22 UTC |
| Last modified on VirusTotal | 2026-09-26 01:32 UTC |
| Last WHOIS update | 2025-11-28 00:00 UTC |
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Vidar. Confidence: 100. First seen: 2026-09-25 08:35:45 UTC. Last seen: 2026-09-25 09:23:15 UTC. Reporter: crep1x. Tags: Vidar.
Remediations (10)
-
web:any.run
Vidar is an information stealer trojan. It is either a fork of Vidar or the result of its evolution. Follow live malware statistics of this trojan and get new reports, samples, IOCs, etc.
-
web:thehackernews.com
Vidar stealer now uses throwaway accounts on social media platforms to retrieve the address of its command-and-control servers and steal information.
-
web:threatfox.abuse.ch
Vidar IOC: hj.1jp88.org ( domain ) You are viewing the ThreatFox database entry for domain hj.1jp88.org .
-
web:www.cyfirma.com
Additionally, it examines their utilization of social media platforms to procure command and control details for data exfiltration and updates. Introduction This study provides a concise overview of Vidar Stealer, a potent malware written in C++, capable of stealing a wide range of data from the compromised system.
-
web:www.hhs.gov
Vidar frequently uses social media as part of its command and control (C2) infrastructure. The IP address of the C2 infrastructure will be embedded in a user profile on platforms like Mastodon, Telegram, etc. The malware can access this profile, contact the indicated IP address, and download configuration files, instructions, and other malware.
-
web:www.huntress.com
Vidar malware is an information-stealing trojan that targets sensitive data, such as login credentials and cryptocurrency wallets. It works by deploying a payload to infected systems, collecting data, and transmitting it to command and control servers controlled by attackers.
-
web:www.intrinsec.com
Figure 3: Vidar main domain inside "information.txt". The specific "reg" subdomain is a login and registration panel for clients of the stealer.
-
web:www.pointwild.com
Initial Infection Vector for Vidar (2026) The initial infection vector for Vidar infostealer in 2026 has significantly evolved from traditional exploit-based delivery to highly user-driven and social engineering-based execution chains.
-
web:www.quorumcyber.com
Vidar is a strain of "information stealer", or "infostealer", malware, compiled in C++, which collects personal information, private documents, and account data from the devices of infected users.
-
web:www.spamhaus.org
The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware-infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.