TF-1815175
high
📛 Threat Title
Vidar: URL that delivers a malware payload https://timothy-miejan.client-demo-websites.com/
Description
Indicator that identifies a malware distribution server (payload delivery). IOC type: URL that delivers a malware payload. Attributed malware: Vidar. Confidence: 75. First seen: 2026-05-16 00:15:04 UTC. Last seen: 2026-05-16 01:30:20 UTC. Reporter: anonymous. Tags: ClickFix, compromised, etherhiding, Polygon, Vidar, WordPress.
Indicators of Compromise (2)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
157.173.204.154
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/157.173.204.154
IOC database
- Type
- ipv4
- Value
157.173.204.154- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Resolved from url https://timothy-miejan.client-demo-websites.com/
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/157.173.204.154
url
https://timothy-miejan.client-demo-websites.com/
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/urls/aHR0cHM6Ly90aW1vdGh5LW1pZWphbi5jbGllbnQtZGVtby13ZWJzaXRlcy5jb20v
UrlVoid 2 / 35
IOC database
- Type
- url
- Value
https://timothy-miejan.client-demo-websites.com/- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- URL that delivers a malware payload attributed to Vidar
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/urls/aHR0cHM6Ly90aW1vdGh5LW1pZWphbi5jbGllbnQtZGVtby13ZWJzaXRlcy5jb20v
References (2)
- Malpedia profile Threatfox IOCs/Threats
-
ThreatFox IOC page
Threatfox IOCs/Threats
Indicator that identifies a malware distribution server (payload delivery). IOC type: URL that delivers a malware payload. Attributed malware: Vidar. Confidence: 75. First seen: 2026-05-16 00:15:04 UTC. Reporter: anonymous. Tags: ClickFix, compromised, etherhiding, Polygon, Vidar, WordPress.
Remediations (8)
-
web:cybersecuritynews.com
Vidar focuses on pulling information that can be converted into financial gain or used to access other systems. Once the loader completes its work and the payload runs, the malware targets browser-stored credentials, saved session cookies, cryptocurrency wallet files, and general system data.
-
web:gbhackers.com
Vidar has evolved from a basic Arkei-based credential stealer into a multi-stage, stealth-focused infostealer that now hides second‑stage payloads within JPEG and TXT files to evade modern defenses. First observed in 2018, Vidar now operates as a mature Malware‑as‑a‑Service (MaaS) with flexible delivery, multi‑stage execution, and strong data‑theft capabilities. Attackers weaponize ...
-
web:www.esentire.com
Dive deeper into the technical details gathered during eSentire's Threat Response Unit (TRU) team's research and threat analysis of the Vidar Stealer malware .
-
web:www.hhs.gov
The malware can access this profile, contact the indicated IP address, and download configuration files, instructions, and other malware . Considering the fact that Vidar—like other stealers—also defaults to performing self-destruction after gathering all the information from the system, it is a rather prolific malware .
-
web:www.huntress.com
Vidar malware is an information-stealing trojan that targets sensitive data, such as login credentials and cryptocurrency wallets. It works by deploying a payload to infected systems, collecting data, and transmitting it to command and control servers controlled by attackers.
-
web:www.levelblue.com
In this Threat Analysis report, we investigate a multi-stage malware execution chain identified through proactive threat hunting activities within a client environment.
-
web:www.malwarebytes.com
We found fake "verify you are human" pages on hacked WordPress sites that trick Windows users into installing the Vidar infostealer.
-
web:www.pointwild.com
Initial Infection Vector for Vidar (2026) The initial infection vector for Vidar infostealer in 2026 has significantly evolved from traditional exploit-based delivery to highly user-driven and social engineering-based execution chains.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.