MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3fcbe89b69925446e12a4be89c67ecf099382aafe4dda15558c83933532df7c1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Vjw0rm


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 3fcbe89b69925446e12a4be89c67ecf099382aafe4dda15558c83933532df7c1
SHA3-384 hash: 2c4dd5370cd8eef76dc58249a3ad19899f299b9a7e738c9147a4d51181e58591f42d71ce5cb919b7462d7c41a7296569
SHA1 hash: a36658757ff6fb522681532f0a127ac50c708829
MD5 hash: 9291e60232fac0fb42180ed92d60dabb
humanhash: jupiter-mobile-utah-spring
File name:Payment Invoice.js
Download: download sample
Signature Vjw0rm
File size:211'013 bytes
First seen:2022-11-01 08:05:50 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 3072:rpne9Y+0nmMDFL5Zof2mIOccg6k7XZlM7VzKMkWiYG98WE5WAHY2:rEO5mQLHzD37plMJ0gWUY2
TLSH T12024DF6A3A946FCB8B8C4018E0E923375EE749459309E207AE7AFF05F6D7B40D4453B6
Reporter abuse_ch
Tags:js vjw0rm


Avatar
abuse_ch
Vjw0rm C2:
109.206.243.106:3608

Intelligence


File Origin
# of uploads :
1
# of downloads :
279
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm evasive obfuscated
Result
Threat name:
VjW0rm, STRRAT
Detection:
malicious
Classification:
troj.expl.evad
Score:
100 / 100
Signature
Antivirus detection for URL or domain
Drops script or batch files to the startup folder
JavaScript source code contains functionality to generate code involving a shell, file or stream
JScript performs obfuscated calls to suspicious functions
Malicious sample detected (through community Yara rule)
Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes)
Sigma detected: Drops script at startup location
Sigma detected: VjW0rm
System process connects to network (likely due to code injection or exploit)
Yara detected AllatoriJARObfuscator
Yara detected STRRAT
Yara detected VjW0rm
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 735019 Sample: Payment Invoice.js Startdate: 01/11/2022 Architecture: WINDOWS Score: 100 40 sonatype.map.fastly.net 2->40 42 repo1.maven.org 2->42 44 github.com 2->44 48 Malicious sample detected (through community Yara rule) 2->48 50 Antivirus detection for URL or domain 2->50 52 Yara detected VjW0rm 2->52 54 5 other signatures 2->54 9 wscript.exe 3 3 2->9         started        13 wscript.exe 12 2->13         started        signatures3 process4 dnsIp5 28 C:\Users\user\AppData\Roaming\lonjygtjp.txt, Zip 9->28 dropped 30 C:\Users\user\AppData\Roaming\cpOiZUlDYK.js, ASCII 9->30 dropped 56 System process connects to network (likely due to code injection or exploit) 9->56 58 JScript performs obfuscated calls to suspicious functions 9->58 60 Drops script or batch files to the startup folder 9->60 62 Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes) 9->62 16 wscript.exe 1 13 9->16         started        20 javaw.exe 23 9->20         started        46 javaautorun.duia.ro 13->46 file6 signatures7 process8 dnsIp9 32 javaautorun.duia.ro 41.217.12.189, 5465 SpectranetNG Nigeria 16->32 26 C:\Users\user\AppData\...\cpOiZUlDYK.js, ASCII 16->26 dropped 34 140.82.121.3, 443, 49783, 49786 GITHUBUS United States 20->34 36 github.com 140.82.121.4, 443, 49701, 49703 GITHUBUS United States 20->36 38 3 other IPs or domains 20->38 22 icacls.exe 1 20->22         started        file10 process11 process12 24 conhost.exe 22->24         started       
Threat name:
Script-JS.Trojan.Cryxos
Status:
Malicious
First seen:
2022-11-01 08:06:06 UTC
File Type:
Text (JavaScript)
AV detection:
4 of 40 (10.00%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:strrat family:vjw0rm persistence stealer trojan worm
Behaviour
Creates scheduled task(s)
Modifies registry class
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Drops file in Program Files directory
Adds Run key to start application
Looks up external IP address via web service
Checks computer location settings
Drops startup file
Loads dropped DLL
Blocklisted process makes network request
STRRAT
Vjw0rm
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BitcoinAddress
Author:Didier Stevens (@DidierStevens)
Description:Contains a valid Bitcoin address

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments