s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1811930 high

📛 Threat Title

Vidar: Domain that is used for botnet Command&control (C&C) sil.loniluekegerman.com

Category: Vidar Published: Source updated: First seen: Last updated: Source: Threatfox IOCs/Threats

Description

Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Vidar. Confidence: 100. First seen: 2026-05-13 19:00:13 UTC. Reporter: crep1x. Tags: Vidar.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

ipv4 104.21.22.188 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.21.22.188

IOC database

Type
ipv4
Value
104.21.22.188
First seen
Last seen
Attached to this threat
Appears in
4 threats
Description
Resolved from domain sil.loniluekegerman.com

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.21.22.188

ipv4 172.67.206.161 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/172.67.206.161

IOC database

Type
ipv4
Value
172.67.206.161
First seen
Last seen
Attached to this threat
Appears in
4 threats
Description
Resolved from domain sil.loniluekegerman.com

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/172.67.206.161

domain sil.loniluekegerman.com VT 19 / 91 UrlVoid 5 / 35 1 feed

IOC database

Type
domain
Value
sil.loniluekegerman.com
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Domain that is used for botnet Command&control (C&C) attributed to Vidar

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Flagged by 19 of 91 VirusTotal vendors

VendorVerdictDetection
ADMINUSLabs malicious malicious
AlphaSOC malicious malware
BitDefender malicious phishing
Chong Lua Dao malicious malicious
CRDF malicious malicious
CyRadar malicious malicious
Dr.Web malicious malicious
Fortinet malicious malware
G-Data malicious phishing
LevelBlue malicious phishing
Lionic malicious malicious
MalwareURL malicious malware
Seclookup malicious malicious
Sophos malicious phishing
VIPRE malicious malware
Webroot malicious malicious
Certego suspicious suspicious
ESET suspicious suspicious
SOCRadar suspicious suspicious

Details From VirusTotal

Basic Properties
TLDcom
History
Creation date2025-12-24 00:00 UTC
Last analysis2026-06-11 10:26 UTC
Last modified on VirusTotal2026-06-15 07:50 UTC
Last WHOIS update2025-12-24 00:00 UTC

References (2)

  • Malpedia profile Threatfox IOCs/Threats
  • ThreatFox IOC page Threatfox IOCs/Threats

    Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Vidar. Confidence: 100. First seen: 2026-05-13 19:00:13 UTC. Reporter: crep1x. Tags: Vidar.

Remediations (10)

  • web:101.school

    Command and Control (C&C) servers play a crucial role in the operation of botnets and other forms of malware. They serve as the central hub from which cybercriminals can control infected machines, known as 'bots'.

  • web:docs.fortinet.com

    From your internal network PC, use a command line tool, such as dig or nslookup, to query this domain and verify that it is blocked by the DNS filter botnet C&C .

  • web:eln0ty.github.io

    Deep Analysis of Vidar Information Stealer 17 minute read On this page Vidar overview Sample Preparation (strings & dlls) Decrypt strings Building imports C2 Server How to understand the configuration format Folder generation Browsers 2 Factor Authentication software (2FA) Messengers Crypto Wallets Information log Result Other payloads Kill Task Exfiltration Conclusion Yara Rules Vidar (forked ...

  • web:engineering.purdue.edu

    the computers in a network and is independent of botnet architectures and the means used for their command and control. As practically all aspects of how a botnet manifests itself in a network, such as the online bot population, bot lifetimes, and the duration and the choice of malicious activities ordered by the bot master, can be expected to ...

  • web:networkthreatdetection.com

    Learn how recognizing botnet command and control patterns reveals hidden threats and keeps your network safe from malicious attacks.

  • web:pwn.guide

    These servers enable an attacker to control and manage a network of compromised systems, forming a botnet . C&C servers provide a centralized command interface, allowing attackers to issue commands, upload and download files, update malware, and exfiltrate data from the compromised systems.

  • web:thehackernews.com

    Vidar stealer now uses throwaway accounts on social media platforms to retrieve the address of its command-and-control servers and steal information.

  • web:www.censys.com

    Vidar Operational Details Vidar uses common network communication methods, and once in place, it will connect to a Telegram server to fetch the URL of the Command and Control (C2) server. In the following two screenshots, you will see examples of this C2 distribution method via Telegram or, if that fails, a backup Steam account.

  • web:www.crowdstrike.com

    What are command and control attacks? C&C (also known as C2) is a method that cybercriminals use to communicate with compromised devices within a target company's network. In a C&C attack, an attacker uses a server to send commands to — and receive data from — computers compromised by malware. This server is also known as a C2 or C&C server.

  • web:www.spamhaus.org

    The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware-infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

VirusTotal Information

loading…

IP Geolocation

Loading…