🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 54b582961ebc52c5017f65743f7e96715ca76ac77a285708f33e76cf6159cecd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Vjw0rm


Vendor detections: 6


Intelligence 6 IOCs 1 YARA File information Comments

SHA256 hash: 54b582961ebc52c5017f65743f7e96715ca76ac77a285708f33e76cf6159cecd
SHA3-384 hash: 904fc9bed5a879183a878df2959c340c7be2c5e7c11eb064e5b343c2e26b35fd7904324ffaf54f42b37b4a9496ea9e3d
SHA1 hash: 022c845c213e2cc1b311e37a1ee9eae32410441e
MD5 hash: 422a51830d190a1e37b9a45c05ce539a
humanhash: saturn-sixteen-hawaii-freddie
File name:#00957.js
Download: download sample
Signature Vjw0rm
File size:9'577 bytes
First seen:2021-12-13 18:54:21 UTC
Last seen:2021-12-14 06:59:02 UTC
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 192:tq17hrtlYa6IxyD6StNkfDk5h33lZTdcVFgnPPcpG6iZsN:tq17hZf6ND6uifDGhlZmFWf6iZE
TLSH T1CA12BF8F27C650B244834708CA4BCDAC7F794DB09480FB7545C6AA4E34F2E2695F395A
Reporter abuse_ch
Tags:js vjw0rm

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
http://decebermoney.duckdns.org:8022/Vre https://threatfox.abuse.ch/ioc/275426/

Intelligence


File Origin
# of uploads :
3
# of downloads :
249
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-vm
Threat name:
Script-JS.Trojan.Heuristic
Status:
Malicious
First seen:
2021-12-13 18:55:10 UTC
File Type:
Text (JavaScript)
AV detection:
12 of 45 (26.67%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:vjw0rm persistence trojan worm
Behaviour
Creates scheduled task(s)
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Adds Run key to start application
Drops startup file
Blocklisted process makes network request
Vjw0rm
Malware Config
C2 Extraction:
http://decebermoney.duckdns.org:8022
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Vjw0rm

Java Script (JS) js 54b582961ebc52c5017f65743f7e96715ca76ac77a285708f33e76cf6159cecd

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments