🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 036046d5ad198798908412fb75cb37ddc9dba5bbf7397b397a7d75ab3e7f7956. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Vjw0rm


Vendor detections: 7


Intelligence 7 IOCs 1 YARA 1 File information Comments

SHA256 hash: 036046d5ad198798908412fb75cb37ddc9dba5bbf7397b397a7d75ab3e7f7956
SHA3-384 hash: 079bdffa64eb701124c84d4806d455ae4c313c4701c6c44176c114473ede393423069ef702ac44a6f01a2a1adb461125
SHA1 hash: 2762322525e6205038d8514deaab9bd24ac2a9e9
MD5 hash: 4d13e3eb8679c9a8a1a95ee8c363e707
humanhash: hawaii-oven-magnesium-quiet
File name:cLAskPOVmATadexax2223.js
Download: download sample
Signature Vjw0rm
File size:23'143 bytes
First seen:2022-08-23 01:55:36 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 384:8yxoLzQecGqaGQlu2SRCiG0/Q0z0lptkwg8QEssA32DDFMe:8yxoLzQecGGQ49oSCJg8pssA32DDFMe
TLSH T101A260EC7895F88CC6649624B6282DE4E3E5670FD04013CF782C724A9FB1A44D7EE979
Reporter abuse_ch
Tags:js vjw0rm


Avatar
abuse_ch
Vjw0rm C2:
http://185.157.162.75:2223/Vre

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
http://185.157.162.75:2223/Vre https://threatfox.abuse.ch/ioc/844808/

Intelligence


File Origin
# of uploads :
1
# of downloads :
353
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-vm evasive obfuscated
Result
Threat name:
Detection:
malicious
Classification:
troj.expl.evad
Score:
100 / 100
Signature
Drops script or batch files to the startup folder
JavaScript source code contains functionality to generate code involving a shell, file or stream
JScript performs obfuscated calls to suspicious functions
Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes)
Sigma detected: Drops script at startup location
Snort IDS alert for network traffic
System process connects to network (likely due to code injection or exploit)
Uses known network protocols on non-standard ports
Wscript called in batch mode (surpress errors)
Yara detected VjW0rm
Behaviour
Behavior Graph:
Threat name:
Script.Worm.Heuristic
Status:
Malicious
First seen:
2022-08-23 01:56:07 UTC
File Type:
Text (JavaScript)
AV detection:
2 of 40 (5.00%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:vjw0rm trojan worm
Behaviour
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Drops startup file
Blocklisted process makes network request
Vjw0rm
Malware Config
C2 Extraction:
http://185.157.162.75:2223
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_obfuscated_JS_obfuscatorio
Author:@imp0rtp3
Description:Detect JS obfuscation done by the js obfuscator (often malicious)
Reference:https://obfuscator.io

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments