🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 383ce97511c3f308482000d1d303cb4a6ec072d0ec3084c0522ef0e2351bccd9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Vjw0rm


Vendor detections: 5


Intelligence 5 IOCs 1 YARA File information Comments

SHA256 hash: 383ce97511c3f308482000d1d303cb4a6ec072d0ec3084c0522ef0e2351bccd9
SHA3-384 hash: 75cdc5e8c46df32f720e1111b429e3d4a598dd714876c68b947e5001027d2759d0913852fb795cb1b0d9540db24902b5
SHA1 hash: 6c09c49272c34917b18cf4888dda1e64fc51360d
MD5 hash: d79e90f5a36512261c3108cbe6637acd
humanhash: pluto-uranus-mountain-golf
File name:ID829301992003.js
Download: download sample
Signature Vjw0rm
File size:30'522 bytes
First seen:2021-04-21 03:20:44 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 768:BrK+dSVssu8law5DOSaduUpbIQzvii/e5F:BrKqSVPu8law5DOSaduUpbIQzvii/e5F
TLSH 15D2EE512315DA81DCA0F7A168A3A8DB157AC1B081D5E0CDEC898D1DAD3CF657D0FBC6
Reporter abuse_ch
Tags:js vjw0rm


Avatar
abuse_ch
Vjw0rm C2:
http://185.81.158.167:8706/Vre

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
http://185.81.158.167:8706/Vre https://threatfox.abuse.ch/ioc/9338/

Intelligence


File Origin
# of uploads :
1
# of downloads :
110
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Script-JS.Downloader.SLoad
Status:
Malicious
First seen:
2021-04-22 10:29:54 UTC
AV detection:
12 of 47 (25.53%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:vjw0rm trojan worm
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Drops startup file
Blocklisted process makes network request
Vjw0rm
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments