Finding CF-3028
High exposure on scada-vendor.meridianenergy.example
Mark in progressFalse positive
HighIn progress
Third-partyDetected 2026-07-12 20:54Seen 1× across sourcesCredential evidence
Passwords are masked — full values require reveal permission- Identity
- [email protected]
- Login URL
- https://scada-vendor.meridianenergy.example
- Password
- Nb9••••••
- Matched asset
- scada-vendor.meridianenergy.example
- First seen in log
- 2026-07-12
Infected device
- Device
- DESKTOP-9RT2K1
- Operating system
- Windows 10 Pro 22H2
- IP at capture
- 198.51.100.48
- Country
- Poland
- Infected at
- 2026-07-12 12:52
- Antivirus
- Not detected in log
Source block
- Block
- BLK-88124
- Stealer family
- Vidar
- Posted
- 2026-07-12 06:41
- Channel
- Telegram cloud-of-logs
- Lines in block
- 1,292
Related findings
Triage timeline
2026-07-12 20:54 · System
Finding created from stealer block and matched to asset scada-vendor.meridianenergy.example
2026-07-12 20:54 · System
Severity set to High based on asset criticality and credential context
2026-07-12 09:30 · A. Analyst
Status changed to In progress
Awaiting next analyst action