🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7209b5eaae21d79e72ea7fad3fdf9430e4f6fa4c4011c29fdedb71035f35e0b9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Vjw0rm


Vendor detections: 4


Intelligence 4 IOCs 1 YARA File information Comments

SHA256 hash: 7209b5eaae21d79e72ea7fad3fdf9430e4f6fa4c4011c29fdedb71035f35e0b9
SHA3-384 hash: 47286ba075879670aaca540cf788b0b900b3124bef23b7b8c58cf49fef22e4fcab62882a47fd3938f67e48c321f2f497
SHA1 hash: 9833e954338d45830ab5603486319f4a46ceca01
MD5 hash: d720234b5136a9aab99e6bb59b6f45c5
humanhash: twelve-autumn-oscar-fillet
File name:NOTIFICACION DE TRANSFERENCIA VIRTUAL EXITOSA.js
Download: download sample
Signature Vjw0rm
File size:2'562'938 bytes
First seen:2021-05-06 21:21:18 UTC
Last seen:2021-05-06 22:10:51 UTC
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 24576:zr02WmJhZcEv7QJuqbpYCg27z5lugqgFsNADLM6UW8hMz9LeAGZDPApZlfLeU3DI:t0fsBmu
TLSH C2C59D50BE945AF9EF8D1D0ED06EAB1DC7F042172D22706BFA516F02B9DB146810B26F
Reporter abuse_ch
Tags:js vjw0rm


Avatar
abuse_ch
Vjw0rm C2:
http://8903.duckdns.org:7003/Vre

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
http://8903.duckdns.org:7003/Vre https://threatfox.abuse.ch/ioc/30636/

Intelligence


File Origin
# of uploads :
2
# of downloads :
117
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Script-JS.Trojan.Heuristic
Status:
Malicious
First seen:
2021-05-06 21:22:17 UTC
AV detection:
3 of 47 (6.38%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:vjw0rm trojan worm
Behaviour
Enumerates physical storage devices
Drops startup file
Blocklisted process makes network request
Vjw0rm
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments