🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 29ea901e52ccc57b80dbcf639ae63a45e704960ebe97f6c957e22c0f61e2e88b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Vjw0rm


Vendor detections: 7


Intelligence 7 IOCs 1 YARA File information Comments

SHA256 hash: 29ea901e52ccc57b80dbcf639ae63a45e704960ebe97f6c957e22c0f61e2e88b
SHA3-384 hash: 4cd0631ca666a7254a95bb9544a41ddb259019ad943096139d5aa35b97e0ce11e6ab3af341f32a1849b6f8c6a77abeef
SHA1 hash: 9a4aa8045782bd40df865ac4c35151a5d11ddee2
MD5 hash: d0ba0fe21bf9d8fb4e03d08a326f8f56
humanhash: july-white-july-lamp
File name:Voicemailmessage102210.js
Download: download sample
Signature Vjw0rm
File size:47'800 bytes
First seen:2022-05-11 16:56:01 UTC
Last seen:2022-05-12 05:34:44 UTC
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 768:B0CdxROcFKJ5tFqL5rukQqxU1UtRv3wsahd6Rdf9XgdHZq+IrK:B0kxRoFq1DdO1UtB3w7dudf9XgJyK
TLSH T19423F5CC7D61A0AECAA895767C3E2CC947F4624BE042938E360F72001BB9749DB9E55C
Reporter abuse_ch
Tags:js vjw0rm


Avatar
abuse_ch
Vjw0rm C2:
http://severdops.ddns.net:5050/Vre

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
http://severdops.ddns.net:5050/Vre https://threatfox.abuse.ch/ioc/549637/

Intelligence


File Origin
# of uploads :
3
# of downloads :
444
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm evasive explorer.exe schtasks schtasks.exe wscript wscript.exe
Result
Threat name:
Detection:
malicious
Classification:
troj.expl.evad
Score:
100 / 100
Signature
Antivirus detection for URL or domain
Creates multiple autostart registry keys
Drops script or batch files to the startup folder
JavaScript source code contains call to eval containing suspicious API calls
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Potential malicious VBS/JS script found (suspicious encoded strings)
Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes)
Sigma detected: Drops script at startup location
Snort IDS alert for network traffic
System process connects to network (likely due to code injection or exploit)
Uses dynamic DNS services
Uses known network protocols on non-standard ports
Uses schtasks.exe or at.exe to add and modify task schedules
Wscript called in batch mode (surpress errors)
Yara detected VjW0rm
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 624536 Sample: Voicemailmessage102210.js Startdate: 11/05/2022 Architecture: WINDOWS Score: 100 62 Snort IDS alert for network traffic 2->62 64 Multi AV Scanner detection for domain / URL 2->64 66 Antivirus detection for URL or domain 2->66 68 7 other signatures 2->68 7 wscript.exe 2 17 2->7         started        12 wscript.exe 13 2->12         started        14 wscript.exe 13 2->14         started        16 5 other processes 2->16 process3 dnsIp4 58 severdops.ddns.net 62.197.136.69, 49734, 49746, 49750 SPRINTLINKUS Netherlands 7->58 60 192.168.2.1 unknown unknown 7->60 50 C:\Users\user\AppData\Roaming\cMoAdVmvFS.js, ASCII 7->50 dropped 52 Voicemailmessage10....js:Zone.Identifier, ASCII 7->52 dropped 54 C:\Users\user\...\Voicemailmessage102210.js, ASCII 7->54 dropped 56 2 other malicious files 7->56 dropped 72 System process connects to network (likely due to code injection or exploit) 7->72 74 Drops script or batch files to the startup folder 7->74 76 Creates multiple autostart registry keys 7->76 80 2 other signatures 7->80 18 wscript.exe 1 7 7->18         started        21 schtasks.exe 1 7->21         started        78 Wscript called in batch mode (surpress errors) 12->78 23 wscript.exe 12->23         started        26 schtasks.exe 12->26         started        28 schtasks.exe 1 14->28         started        30 wscript.exe 14->30         started        32 schtasks.exe 1 16->32         started        34 schtasks.exe 1 16->34         started        36 2 other processes 16->36 file5 signatures6 process7 file8 48 C:\Users\user\AppData\...\cMoAdVmvFS.js, ASCII 18->48 dropped 38 conhost.exe 21->38         started        70 Creates multiple autostart registry keys 23->70 40 conhost.exe 26->40         started        42 conhost.exe 28->42         started        44 conhost.exe 32->44         started        46 conhost.exe 34->46         started        signatures9 process10
Threat name:
Script-JS.Trojan.Cryxos
Status:
Malicious
First seen:
2022-05-11 16:56:05 UTC
File Type:
Text (JavaScript)
AV detection:
6 of 41 (14.63%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:vjw0rm persistence trojan worm
Behaviour
Creates scheduled task(s)
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Adds Run key to start application
Checks computer location settings
Drops startup file
Blocklisted process makes network request
Vjw0rm
Malware Config
C2 Extraction:
http://severdops.ddns.net:5050
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Vjw0rm

Java Script (JS) js 29ea901e52ccc57b80dbcf639ae63a45e704960ebe97f6c957e22c0f61e2e88b

(this sample)

Comments