🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8f725c902bf561f62cc1a3331460aa5fa6ab08e9e54fdebf6ebcd476a2ab8982. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Vjw0rm


Vendor detections: 11


Intelligence 11 IOCs 1 YARA 2 File information Comments

SHA256 hash: 8f725c902bf561f62cc1a3331460aa5fa6ab08e9e54fdebf6ebcd476a2ab8982
SHA3-384 hash: 999388a8cb1d05ddf25289867ac6eb800f38c042ff41beb7763bfd9c076f2ce510e256979dc435b3137cca8441469386
SHA1 hash: 4f1510ba12e1d90b11169326a3d8ee847383c329
MD5 hash: 44ced2e7e68074eeab69c861726736b3
humanhash: leopard-yankee-coffee-king
File name:8F725C902BF561F62CC1A3331460AA5FA6AB08E9E54FD.exe
Download: download sample
Signature Vjw0rm
File size:13'843'456 bytes
First seen:2022-08-26 06:50:40 UTC
Last seen:2022-08-26 07:42:47 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'245 x AgentTesla, 20'500 x Formbook, 12'374 x SnakeKeylogger)
ssdeep 393216:hG1uv/z3OcitnplQ8p2DG82n/YcV2JZAeV3I9HI:4Ivn0plQ8pbUZA83C
Threatray 50 similar samples on MalwareBazaar
TLSH T1E5D63309EBF649DCCCC17FB140B2062562FD0F8E2A729BBDD527B58407325E44A5E68B
TrID 69.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
9.9% (.EXE) Win64 Executable (generic) (10523/12/4)
6.2% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.7% (.EXE) Win16 NE executable (generic) (5038/12/1)
4.2% (.EXE) Win32 Executable (generic) (4505/5/1)
File icon (PE):PE icon
dhash icon 1ec0c4e4e4c4c01e (1 x RedLineStealer, 1 x Vjw0rm, 1 x Loki)
Reporter abuse_ch
Tags:exe vjw0rm


Avatar
abuse_ch
Vjw0rm C2:
http://kraldeli.linkpc.net:1/Vre

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
http://kraldeli.linkpc.net:1/Vre https://threatfox.abuse.ch/ioc/845496/

Intelligence


File Origin
# of uploads :
2
# of downloads :
309
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
8F725C902BF561F62CC1A3331460AA5FA6AB08E9E54FD.exe
Verdict:
Suspicious activity
Analysis date:
2022-08-26 06:58:27 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
Creating a file in the %AppData% directory
Creating a process from a recently created file
Creating a window
Creating a file
Using the Windows Management Instrumentation requests
Creating a process with a hidden window
Launching a process
Creating a file in the %temp% directory
DNS request
Sending a custom TCP request
Searching for synchronization primitives
Enabling the 'hidden' option for recently created files
Unauthorized injection to a recently created process
Downloading the file
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Query of malicious DNS domain
Creating a file in the mass storage device
Enabling autorun by creating a file
Unauthorized injection to a system process
Enabling threat expansion on mass storage devices
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
packed quasar
Result
Threat name:
Detection:
malicious
Classification:
troj.expl.evad
Score:
100 / 100
Signature
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
.NET source code references suspicious native API functions
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Creates processes via WMI
Drops script or batch files to the startup folder
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes)
Sigma detected: Drops script at startup location
Sigma detected: Powershell download and execute file
Suspicious powershell command line found
System process connects to network (likely due to code injection or exploit)
Uses schtasks.exe or at.exe to add and modify task schedules
Writes to foreign memory regions
Wscript starts Powershell (via cmd or directly)
Yara detected Generic Downloader
Yara detected Powershell download and execute
Yara detected VjW0rm
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 690730 Sample: 8F725C902BF561F62CC1A333146... Startdate: 26/08/2022 Architecture: WINDOWS Score: 100 89 sabifati34.mywire.org 2->89 105 Multi AV Scanner detection for domain / URL 2->105 107 Malicious sample detected (through community Yara rule) 2->107 109 Antivirus detection for URL or domain 2->109 111 14 other signatures 2->111 9 8F725C902BF561F62CC1A3331460AA5FA6AB08E9E54FD.exe 3 10 2->9         started        12 wscript.exe 2->12         started        14 wscript.exe 2->14         started        18 4 other processes 2->18 signatures3 process4 dnsIp5 81 C:\Users\user\...\Microsoft Toolkit.exe, PE32 9->81 dropped 83 C:\Users\user\AppData\Roaming\acluyi.dll.js, ASCII 9->83 dropped 85 8F725C902BF561F62C...AB08E9E54FD.exe.log, ASCII 9->85 dropped 20 wscript.exe 2 14 9->20         started        25 wscript.exe 1 1 9->25         started        39 2 other processes 9->39 27 cscript.exe 12->27         started        95 kraldeli.linkpc.net 14->95 127 System process connects to network (likely due to code injection or exploit) 14->127 129 Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes) 14->129 29 schtasks.exe 14->29         started        97 thearakanpost.com 18->97 99 kraldeli.linkpc.net 18->99 101 2 other IPs or domains 18->101 31 schtasks.exe 18->31         started        33 schtasks.exe 18->33         started        35 schtasks.exe 18->35         started        37 conhost.exe 18->37         started        file6 signatures7 process8 dnsIp9 93 kraldeli.linkpc.net 84.51.52.166, 1, 49732, 49735 TELLCOM-ASTR Turkey 20->93 77 C:\Users\user\AppData\...\aclui.dll.js, Little-endian 20->77 dropped 79 C:\Users\user\AppData\Local\...\aclui.dll.js, Little-endian 20->79 dropped 113 Wscript starts Powershell (via cmd or directly) 20->113 115 Drops script or batch files to the startup folder 20->115 117 Uses schtasks.exe or at.exe to add and modify task schedules 20->117 119 2 other signatures 20->119 41 schtasks.exe 1 20->41         started        43 xcopy.exe 25->43         started        47 powershell.exe 15 24 25->47         started        50 powershell.exe 27->50         started        60 2 other processes 27->60 52 conhost.exe 29->52         started        54 conhost.exe 31->54         started        56 conhost.exe 33->56         started        58 conhost.exe 35->58         started        file10 signatures11 process12 dnsIp13 62 conhost.exe 41->62         started        87 C:\Users\user\AppData\...\acluyi.dll.js, ASCII 43->87 dropped 121 Drops script or batch files to the startup folder 43->121 64 conhost.exe 43->64         started        103 thearakanpost.com 150.95.96.70, 443, 49733, 49734 GMO-Z-COM-THGMO-ZcomNetDesignHoldingsCoLtdSG Singapore 47->103 66 RegSvcs.exe 47->66         started        69 conhost.exe 47->69         started        123 Writes to foreign memory regions 50->123 125 Injects a PE file into a foreign processes 50->125 71 conhost.exe 50->71         started        73 RegSvcs.exe 50->73         started        75 conhost.exe 60->75         started        file14 signatures15 process16 dnsIp17 91 sabifati34.mywire.org 46.1.54.232, 6552 MILLENICOM-ASDE Turkey 66->91
Threat name:
Win32.Worm.Jenxcus
Status:
Malicious
First seen:
2022-08-24 23:36:00 UTC
File Type:
PE (.Net Exe)
Extracted files:
17
AV detection:
20 of 26 (76.92%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:njrat family:vjw0rm persistence trojan worm
Behaviour
Creates scheduled task(s)
Enumerates system info in registry
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Drops file in System32 directory
Suspicious use of SetThreadContext
Adds Run key to start application
Checks computer location settings
Drops startup file
Loads dropped DLL
Blocklisted process makes network request
Executes dropped EXE
Process spawned unexpected child process
Vjw0rm
njRAT/Bladabindi
Malware Config
Dropper Extraction:
https://thearakanpost.com/forms/scv.flv
https://thearakanpost.com/img/min.exe
Unpacked files
SH256 hash:
f46c91176f9bfbf4c9234000e724d0314bacd98dd4f5f145a89416584187a2ac
MD5 hash:
395b44774eddc465ad48a8411eabe4ab
SHA1 hash:
c94317ca1107ae3a92a556de20bbc17f570eab49
SH256 hash:
e0b9d9f25ae11466ed94ce6c3bed06a82de902e0413c8d72acd7e32b67398814
MD5 hash:
7264d1da56676634424093bc8ee576a8
SHA1 hash:
ac989ad8e970cf76d09f10f715a8cc38298c274e
SH256 hash:
a370526405bbabad034b3aa39d737a4ae2d178654a21eca70ee8f8a9b378ddf2
MD5 hash:
a1559d344a7125e9338e823c246a04d3
SHA1 hash:
9855d787855e42444e3f25e8401c48b334b2cbd7
SH256 hash:
98f2d46d4eb7c490c649fb4eb2b32d81e85c31d06ed02dbfd9617f0c2e2d8e73
MD5 hash:
ac4d92b0e044f0f1450d0e63b73821c3
SHA1 hash:
931574cf46b25aabff24481fe31a43f6ce780e68
SH256 hash:
8f25f2bddfaab8831b7d34d182d98edb83e04434e6891006abc60a84081aa1aa
MD5 hash:
e34a834206a4344af1d803b22232d5ed
SHA1 hash:
6da6e8e423da4449933bdec6ef147a510644c62a
SH256 hash:
8693c647f29f39a90e8ad6da0e8a792ca6e90b961166d68bdbc0059d3111975c
MD5 hash:
4656309dff111c809c8aca0df7a32354
SHA1 hash:
1e978061a0d4cb9a566d4b6b5d6049ea673931dc
Detections:
win_vigilant_cleaner_auto
SH256 hash:
039860c4feef565e0a709a85d3297cdfb550f6844f08093021b9c9855114be83
MD5 hash:
43e5ab80d25365c9ac22ef696a9a20a8
SHA1 hash:
eb251037efc15c4be9ebb6eafa101df98548bd9f
SH256 hash:
b01baf61bdad845fb3de5139d7a52a8592a79395ede4726f18ea4b580d2b6807
MD5 hash:
325417a46139b8d762dd3a408fe6b837
SHA1 hash:
e03dea5c6fe135a6350083321fb2bdf017df4595
SH256 hash:
e42f12dc6d3388374fcfd3efccaaea83cb087a87120f21883495d9085ff439b9
MD5 hash:
19082b9bc194254f4442490522d69e76
SHA1 hash:
0f6316344042f5279b688ca9699072bc0d63c670
SH256 hash:
8f725c902bf561f62cc1a3331460aa5fa6ab08e9e54fdebf6ebcd476a2ab8982
MD5 hash:
44ced2e7e68074eeab69c861726736b3
SHA1 hash:
4f1510ba12e1d90b11169326a3d8ee847383c329
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments