MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0a4b4ce43b2e1ad4a97eba5d317b894b08ba5046b0598b0be965dd778cc953bf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Vjw0rm


Vendor detections: 14


Intelligence 14 IOCs 2 YARA File information Comments

SHA256 hash: 0a4b4ce43b2e1ad4a97eba5d317b894b08ba5046b0598b0be965dd778cc953bf
SHA3-384 hash: 882dc97c11794b1c176497dfe53af2d8411c41a9de1456df4bc0eb35fff3935ab22ec6af7aad0f9de21f807c0de2b1f7
SHA1 hash: dd98fc2022c8b8279fffc02d2679a4272c14db7f
MD5 hash: 0e165205ff872a9149660a900b1a0966
humanhash: delta-red-sodium-mobile
File name:ORDER-709856-00251103,PDF.vbs
Download: download sample
Signature Vjw0rm
File size:962'358 bytes
First seen:2025-11-04 14:15:05 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 6144:His5tXNXxZsjCOKebrRAAb1gy9Aum5B1wKPUA6v29ta4MLS/RI:H/5tBshA61gy+umXPUAZOWRI
TLSH T1DD25CD778F619B1A202B4B4965B9CE68D4B4E5F6814288DF35A3E58D20F77132336E3C
Magika vba
Reporter abuse_ch
Tags:vbs vjw0rm


Avatar
abuse_ch
Vjw0rm C2:
46.246.14.7:44662

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
46.246.14.7:44662 https://threatfox.abuse.ch/ioc/1633354/
46.246.14.7:7046 https://threatfox.abuse.ch/ioc/1633355/

Intelligence


File Origin
# of uploads :
1
# of downloads :
76
Origin country :
NL NL
Vendor Threat Intelligence
Verdict:
Malicious
Score:
92.5%
Tags:
autorun houdini dunihi worm
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
base64 cmd evasive explorer lolbin masquerade obfuscated obfuscated persistence wscript
Verdict:
Malicious
File Type:
text
First seen:
2025-11-04T04:22:00Z UTC
Last seen:
2025-11-05T02:03:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan.Script.Generic
Result
Threat name:
WSHRat, Caesium Obfuscator, STRRAT
Detection:
malicious
Classification:
troj.expl.evad
Score:
100 / 100
Signature
Antivirus detection for dropped file
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Connects to many ports of the same IP (likely port scanning)
Creates autostart registry keys to launch java
Creates multiple autostart registry keys
Detected WSHRat
Drops script or batch files to the startup folder
Exploit detected, runtime environment dropped PE file
Exploit detected, runtime environment starts unknown processes
Found malware configuration
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Potential malicious VBS script found (has network functionality)
Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes)
Sigma detected: Drops script at startup location
Sigma detected: Register Wscript In Run Key
Sigma detected: Script Initiated Connection to Non-Local Network
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Suspicious Script Execution From Temp Folder
Sigma detected: Suspicious Startup Folder Persistence
Sigma detected: WScript or CScript Dropper
Sigma detected: WScript or CScript Dropper - File
Suricata IDS alerts for network traffic
System process connects to network (likely due to code injection or exploit)
Uses known network protocols on non-standard ports
Uses schtasks.exe or at.exe to add and modify task schedules
Uses WMIC command to query system information (often done to detect virtual machines)
VBScript performs obfuscated calls to suspicious functions
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Wscript called in batch mode (surpress errors)
Yara detected AllatoriJARObfuscator
Yara detected Caesium Obfuscator
Yara detected STRRAT
Yara detected WSHRAT
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1807790 Sample: ORDER-709856-00251103,PDF.vbs Startdate: 04/11/2025 Architecture: WINDOWS Score: 100 92 chongmei33.publicvm.com 2->92 94 workingboss3.ydns.eu 2->94 96 5 other IPs or domains 2->96 110 Sigma detected: Register Wscript In Run Key 2->110 112 Suricata IDS alerts for network traffic 2->112 114 Found malware configuration 2->114 116 24 other signatures 2->116 12 wscript.exe 3 3 2->12         started        16 wscript.exe 2->16         started        18 wscript.exe 2->18         started        20 5 other processes 2->20 signatures3 process4 file5 88 C:\Users\user\AppData\Local\Temp\java.js, ASCII 12->88 dropped 90 C:\Users\user\AppData\Local\Temp\adobe.js, ASCII 12->90 dropped 134 Detected WSHRat 12->134 136 VBScript performs obfuscated calls to suspicious functions 12->136 138 Drops script or batch files to the startup folder 12->138 142 2 other signatures 12->142 22 wscript.exe 3 2 12->22         started        24 wscript.exe 1 3 12->24         started        140 Wscript called in batch mode (surpress errors) 16->140 28 wscript.exe 16->28         started        signatures6 process7 file8 30 javaw.exe 22 22->30         started        82 C:\Users\user\AppData\Roaming\adobe.js, ASCII 24->82 dropped 84 C:\Users\user\AppData\Roaming\...\adobe.js, ASCII 24->84 dropped 122 Creates multiple autostart registry keys 24->122 124 Windows Scripting host queries suspicious COM object (likely to drop second stage) 24->124 126 Wscript called in batch mode (surpress errors) 24->126 33 wscript.exe 7 24->33         started        128 System process connects to network (likely due to code injection or exploit) 28->128 signatures9 process10 dnsIp11 100 github.com 140.82.113.4, 443, 49690 GITHUBUS United States 30->100 102 release-assets.githubusercontent.com 185.199.110.133, 443, 49695 FASTLYUS Netherlands 30->102 104 repo1.maven.org.cdn.cloudflare.net 104.18.18.12, 443, 49691, 49692 CLOUDFLARENETUS United States 30->104 35 java.exe 30->35         started        106 workingboss3.ydns.eu 46.246.14.7, 44662, 49694, 49697 PORTLANEwwwportlanecomSE Sweden 33->106 process12 file13 78 C:\Users\user\AppData\Roaming\TbR.jar, Zip 35->78 dropped 80 C:\Users\user\AppData\Roaming\...\TbR.jar, Zip 35->80 dropped 118 Creates autostart registry keys to launch java 35->118 120 Creates multiple autostart registry keys 35->120 39 java.exe 35->39         started        44 cmd.exe 35->44         started        46 conhost.exe 35->46         started        signatures14 process15 dnsIp16 98 ip-api.com 208.95.112.1, 49702, 80 TUT-ASUS United States 39->98 86 C:\Users\user\...\jna6325040739059149538.dll, PE32 39->86 dropped 130 Uses WMIC command to query system information (often done to detect virtual machines) 39->130 48 cmd.exe 39->48         started        51 cmd.exe 39->51         started        53 cmd.exe 39->53         started        59 2 other processes 39->59 132 Uses schtasks.exe or at.exe to add and modify task schedules 44->132 55 conhost.exe 44->55         started        57 schtasks.exe 44->57         started        file17 signatures18 process19 signatures20 108 Uses WMIC command to query system information (often done to detect virtual machines) 48->108 61 WMIC.exe 48->61         started        64 conhost.exe 48->64         started        66 conhost.exe 51->66         started        68 WMIC.exe 51->68         started        70 conhost.exe 53->70         started        72 WMIC.exe 53->72         started        74 conhost.exe 59->74         started        76 WMIC.exe 59->76         started        process21 signatures22 144 Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes) 61->144
Verdict:
Malware
YARA:
1 match(es)
Tags:
ADODB.Stream DeObfuscated Microsoft.XMLDOM Obfuscated Scripting.FileSystemObject T1059.005 VBScript WScript.Shell
Threat name:
Script-WScript.Trojan.Heuristic
Status:
Malicious
First seen:
2025-11-04 14:16:17 UTC
File Type:
Text (VBS)
AV detection:
10 of 38 (26.32%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:strrat family:wshrat execution persistence stealer trojan
Behaviour
Modifies registry class
Scheduled Task/Job: Scheduled Task
Script User-Agent
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
Drops file in Program Files directory
Drops file in System32 directory
Adds Run key to start application
Looks up external IP address via web service
Checks computer location settings
Drops startup file
Loads dropped DLL
Badlisted process makes network request
STRRAT
Strrat family
WSHRAT
Wshrat family
Malware Config
C2 Extraction:
chongmei33.publicvm.com:44662
jamesrockky.ydns.eu:49703
http://workingboss3.ydns.eu:7046
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments