This hunt detects adversary activity consistent with the Vidar malware family by correlating network and endpoint telemetry against a curated set of 88 known indicators of compromise. Proactively searching for these specific IOCs in Azure Sentinel is critical to identify early-stage infections and prevent lateral movement, given Vidar’s reputation as a high-severity banking trojan that frequently targets financial sectors.
Malware Family: Vidar Total IOCs: 88 IOC Types: sha256_hash, url, sha1_hash, md5_hash
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| url | hxxps://honeyshine.pk/ | payload_delivery | 2026-07-05 | 75% |
| sha256_hash | 5bcd63edfe85569733cd75e76cb89fa3e9b3628694fa66e23e953a6724cb3ed9 | payload | 2026-07-05 | 95% |
| sha1_hash | e8f545c21e8429c7f33158e1cbd25a665cf48916 | payload | 2026-07-05 | 95% |
| md5_hash | d5f708b13d4b70dc6aac1d0a491780a7 | payload | 2026-07-05 | 95% |
| sha256_hash | fcd8643dff51723d1250496b2a8e10d69fb6e2eb4c01c30cbad32bbf54c9ce51 | payload | 2026-07-05 | 95% |
| sha1_hash | 7c7e735265f2b25be141acac89f91f424387e093 | payload | 2026-07-05 | 95% |
| md5_hash | 871c3d3bc610e885318af5669948a07d | payload | 2026-07-05 | 95% |
| sha256_hash | 741eea6f598af241e1337ad567b7c6d52e601309a381f934ab6ce245c7906469 | payload | 2026-07-05 | 95% |
| sha1_hash | 9477e8ca9c28b45f506dd6c50f98c7d15e861afa | payload | 2026-07-05 | 95% |
| md5_hash | cb0451aa69db2baa8973078965893b08 | payload | 2026-07-05 | 95% |
| sha256_hash | 0c4ad7ea7fd1d24186efc73657dd5feed3f7c7243089e4d9eae0b1f63abeb69d | payload | 2026-07-05 | 95% |
| sha1_hash | c8781fb94d3f26d813bb5a55a703dca02121ae3d | payload | 2026-07-05 | 95% |
| md5_hash | dcc568c8a51881d74be42b270ee0e38d | payload | 2026-07-05 | 95% |
| sha256_hash | c11aeec42a7f3c4e7895d37cf403b6900793226444dfc83ad2b85aab152e457c | payload | 2026-07-05 | 95% |
| sha1_hash | 9c76c024469b7605f9ff575d7b5a9c68ebdfe57e | payload | 2026-07-05 | 95% |
| md5_hash | d197145d9ca63ded215154bb64c9dc40 | payload | 2026-07-05 | 95% |
| md5_hash | eb0da5f19b4395355e77c8da57d7266a | payload | 2026-07-05 | 95% |
| sha256_hash | 9eb3e292b091c691943b70fc0e9d6d2c5e5c55727518e40018ba72b27d71e0a3 | payload | 2026-07-05 | 95% |
| sha1_hash | 3170e2e9076e6e7f27dafea941febfc1b994ce51 | payload | 2026-07-05 | 95% |
| md5_hash | f0f29b04fcb7ca3303e900e189eb5549 | payload | 2026-07-05 | 95% |
| md5_hash | d8c5e570415b946b7a157a91377ad6ad | payload | 2026-07-05 | 95% |
| sha256_hash | 4521f532bf22c3155a95a71c4797253680dc60618c74c18522506a603ef43a03 | payload | 2026-07-05 | 95% |
| sha1_hash | ae22f19ee1036f18f42a9fb9cfd203d0f15d6766 | payload | 2026-07-05 | 95% |
| md5_hash | b77d29650850f76aa139cbbf7453a206 | payload | 2026-07-05 | 95% |
| sha256_hash | ebdd2ac5c447807ff3218ae4fe747a681dc1097b64025452acbf7faa1fb17ca4 | payload | 2026-07-05 | 95% |
// Hunt for access to known malicious URLs
// Source: ThreatFox - Vidar
let malicious_urls = dynamic(["https://honeyshine.pk/"]);
UrlClickEvents
| where Url has_any (malicious_urls)
| project Timestamp, AccountUpn, Url, ActionType, IsClickedThrough
| order by Timestamp desc
// Hunt for files matching known malicious hashes
// Source: ThreatFox - Vidar
let malicious_hashes = dynamic(["5bcd63edfe85569733cd75e76cb89fa3e9b3628694fa66e23e953a6724cb3ed9", "e8f545c21e8429c7f33158e1cbd25a665cf48916", "d5f708b13d4b70dc6aac1d0a491780a7", "fcd8643dff51723d1250496b2a8e10d69fb6e2eb4c01c30cbad32bbf54c9ce51", "7c7e735265f2b25be141acac89f91f424387e093", "871c3d3bc610e885318af5669948a07d", "741eea6f598af241e1337ad567b7c6d52e601309a381f934ab6ce245c7906469", "9477e8ca9c28b45f506dd6c50f98c7d15e861afa", "cb0451aa69db2baa8973078965893b08", "0c4ad7ea7fd1d24186efc73657dd5feed3f7c7243089e4d9eae0b1f63abeb69d", "c8781fb94d3f26d813bb5a55a703dca02121ae3d", "dcc568c8a51881d74be42b270ee0e38d", "c11aeec42a7f3c4e7895d37cf403b6900793226444dfc83ad2b85aab152e457c", "9c76c024469b7605f9ff575d7b5a9c68ebdfe57e", "d197145d9ca63ded215154bb64c9dc40", "eb0da5f19b4395355e77c8da57d7266a", "9eb3e292b091c691943b70fc0e9d6d2c5e5c55727518e40018ba72b27d71e0a3", "3170e2e9076e6e7f27dafea941febfc1b994ce51", "f0f29b04fcb7ca3303e900e189eb5549", "d8c5e570415b946b7a157a91377ad6ad", "4521f532bf22c3155a95a71c4797253680dc60618c74c18522506a603ef43a03", "ae22f19ee1036f18f42a9fb9cfd203d0f15d6766", "b77d29650850f76aa139cbbf7453a206", "ebdd2ac5c447807ff3218ae4fe747a681dc1097b64025452acbf7faa1fb17ca4", "d9c7eaaf67ce48be524c2ef9cb3f78fd19bf5b46", "0007e1a20d9443cb815780c52ea1cdfb", "08be0ddd6e5d000404d4c5f27b7a1acf98c12ac4e4e715ae750f4d80f8e830e5", "4cd613e3b2d94d777d30ecfcf62cd0befe0b4842", "76095c93b9c8ec3655df1c6345f9437a", "3d776e8445933dee504ffe673a96480d5313c1e71979faebb74c3c9734b96b31", "5e949d52b9c2d4a35a70d800985818c9b2135d69", "834ee0b48222d8b99475dfd38d5283b9", "0f1bcecd61092de0735dba542259b31c6566a1df62069a0a3287a0a12dcfa4f2", "733cdd58fa430b86a2daeca2e1b795cdbb3511c0", "2344b27221e13bd6fdae3cbf1d71dbd2", "b6fba18b6641eac47499735a0c872814b20bdc65ed491c04769d0e556d2ec40b", "2a6b75235df4ce03bc213a72cecfca0579998d69", "6995d6a1f44b8ba4f5c9971514e082816a8f0eae", "cb6189c15ec116abb50005041e178d74", "337463ea7d1ef14be117bf0461be4dd342794f5919c820173651b9d7a7269ae3", "a87f3e023cff230f8b4bdfa7945e4e43dcc2c0c9", "c2cfd3d5cc6db52356661d50b0374c494c96af73cb0fea33babb9616d4453098", "9cd9c0a79450290b1ac0ea3235df6cd68332cc5a426991fa1d53eb7f19ec5a09", "fb2d549228df09be55ebc41b0d8d77f0c1d1a77b", "cb4da97b8dbf3dd30c9d32d2879c67a2", "ec59758993501d25047672e4c46d33d7489012bf3936832af18896fb1bbef109", "af7c9e5a99e1d7de22f316eb0ccd9c694ed26f90", "f853d193d83029352212ae5135589816", "51c82d82b7e8e89521e4f3259524fbc2a4b8e595", "2ae339b769bb7b5ec637d243e07a349e"]);
DeviceFileEvents
| where SHA256 in (malicious_hashes) or SHA1 in (malicious_hashes) or MD5 in (malicious_hashes)
| project Timestamp, DeviceName, FileName, FolderPath, SHA256, InitiatingProcessFileName
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
DeviceFileEvents | Ensure this data connector is enabled |
UrlClickEvents | Ensure this data connector is enabled |
Here are 4 specific false positive scenarios for the ThreatFox: Vidar IOCs detection rule in an enterprise environment, along with suggested filters or exclusions:
Endpoint Protection Scanning of Quarantine Archives
C:\ProgramData\ThreatFox\Quarantine directory. This directory often contains archived IOC feeds, historical threat intelligence reports, and sample malware binaries used for training models. The EDR engine may flag these static files as matching Vidar IOCs because they contain known signatures of the malware family itself within their metadata or embedded samples.C:\ProgramData\ThreatFox\Quarantine\*) and exclude processes running under the EDR service account (e.g., svc-crowdstrike or LocalSystem) when accessing these paths.Scheduled Threat Intelligence Feed Updates
C:\Temp\ThreatIntelligence\Vidar_Feed_*.json) before distributing them to downstream agents. The detection logic triggers on these legitimate file creations and reads.TaskName: ThreatFox_Daily_Ingest) or filter based on the parent process being the SIEM agent service (e