TF-1811930
high
📛 Threat Title
Vidar: Domain that is used for botnet Command&control (C&C) sil.loniluekegerman.com
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Vidar. Confidence: 100. First seen: 2026-05-13 19:00:13 UTC. Reporter: crep1x. Tags: Vidar.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
104.21.22.188
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.21.22.188
IOC database
- Type
- ipv4
- Value
104.21.22.188- First seen
- Last seen
- Attached to this threat
- Appears in
- 4 threats
- Description
- Resolved from domain sil.loniluekegerman.com
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.21.22.188
ipv4
172.67.206.161
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/172.67.206.161
IOC database
- Type
- ipv4
- Value
172.67.206.161- First seen
- Last seen
- Attached to this threat
- Appears in
- 4 threats
- Description
- Resolved from domain sil.loniluekegerman.com
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/172.67.206.161
domain
sil.loniluekegerman.com
VT 19 / 91
UrlVoid 5 / 35
1 feed
IOC database
- Type
- domain
- Value
sil.loniluekegerman.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Domain that is used for botnet Command&control (C&C) attributed to Vidar
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Flagged by 19 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ADMINUSLabs | malicious | malicious |
| AlphaSOC | malicious | malware |
| BitDefender | malicious | phishing |
| Chong Lua Dao | malicious | malicious |
| CRDF | malicious | malicious |
| CyRadar | malicious | malicious |
| Dr.Web | malicious | malicious |
| Fortinet | malicious | malware |
| G-Data | malicious | phishing |
| LevelBlue | malicious | phishing |
| Lionic | malicious | malicious |
| MalwareURL | malicious | malware |
| Seclookup | malicious | malicious |
| Sophos | malicious | phishing |
| VIPRE | malicious | malware |
| Webroot | malicious | malicious |
| Certego | suspicious | suspicious |
| ESET | suspicious | suspicious |
| SOCRadar | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| TLD | com |
History
| Creation date | 2025-12-24 00:00 UTC |
| Last analysis | 2026-06-11 10:26 UTC |
| Last modified on VirusTotal | 2026-06-15 07:50 UTC |
| Last WHOIS update | 2025-12-24 00:00 UTC |
References (2)
- Malpedia profile Threatfox IOCs/Threats
-
ThreatFox IOC page
Threatfox IOCs/Threats
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Vidar. Confidence: 100. First seen: 2026-05-13 19:00:13 UTC. Reporter: crep1x. Tags: Vidar.
Remediations (10)
-
web:101.school
Command and Control (C&C) servers play a crucial role in the operation of botnets and other forms of malware. They serve as the central hub from which cybercriminals can control infected machines, known as 'bots'.
-
web:docs.fortinet.com
From your internal network PC, use a command line tool, such as dig or nslookup, to query this domain and verify that it is blocked by the DNS filter botnet C&C .
-
web:eln0ty.github.io
Deep Analysis of Vidar Information Stealer 17 minute read On this page Vidar overview Sample Preparation (strings & dlls) Decrypt strings Building imports C2 Server How to understand the configuration format Folder generation Browsers 2 Factor Authentication software (2FA) Messengers Crypto Wallets Information log Result Other payloads Kill Task Exfiltration Conclusion Yara Rules Vidar (forked ...
-
web:engineering.purdue.edu
the computers in a network and is independent of botnet architectures and the means used for their command and control. As practically all aspects of how a botnet manifests itself in a network, such as the online bot population, bot lifetimes, and the duration and the choice of malicious activities ordered by the bot master, can be expected to ...
-
web:networkthreatdetection.com
Learn how recognizing botnet command and control patterns reveals hidden threats and keeps your network safe from malicious attacks.
-
web:pwn.guide
These servers enable an attacker to control and manage a network of compromised systems, forming a botnet . C&C servers provide a centralized command interface, allowing attackers to issue commands, upload and download files, update malware, and exfiltrate data from the compromised systems.
-
web:thehackernews.com
Vidar stealer now uses throwaway accounts on social media platforms to retrieve the address of its command-and-control servers and steal information.
-
web:www.censys.com
Vidar Operational Details Vidar uses common network communication methods, and once in place, it will connect to a Telegram server to fetch the URL of the Command and Control (C2) server. In the following two screenshots, you will see examples of this C2 distribution method via Telegram or, if that fails, a backup Steam account.
-
web:www.crowdstrike.com
What are command and control attacks? C&C (also known as C2) is a method that cybercriminals use to communicate with compromised devices within a target company's network. In a C&C attack, an attacker uses a server to send commands to — and receive data from — computers compromised by malware. This server is also known as a C2 or C&C server.
-
web:www.spamhaus.org
The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware-infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.