🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 99c182e8011f4dfea584e66768fc3b4e8d50f4d21df5aff433bbd2c7d7217f7d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Vjw0rm


Vendor detections: 8


Intelligence 8 IOCs 1 YARA 1 File information Comments

SHA256 hash: 99c182e8011f4dfea584e66768fc3b4e8d50f4d21df5aff433bbd2c7d7217f7d
SHA3-384 hash: 5af0a8793cf3f802a8529fc0f67937456375d2784de5e253031a11a6e9c949af917b78ea0299eebc3ea37bfe9f113bfd
SHA1 hash: 241f176b6e179c2eade0de0203ef08c64cda5d46
MD5 hash: c540ae3a76bde78418e3e7f9d9b2b3ea
humanhash: november-failed-fix-jersey
File name:Details.js
Download: download sample
Signature Vjw0rm
File size:29'055 bytes
First seen:2022-09-30 13:40:53 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 768:0CGF9Wt5vuE/eSaTX5JSwUr/iF2diLvKL:eAa+jr/A2diLvKL
TLSH T160D28F726D0DDEE8DF90408093FAFF1B176E9B827219244EC251A28037E1AB5521F67E
Reporter proxylife
Tags:js vjw0rm

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
http://kingshakes.ddns.net:6161/Vre https://threatfox.abuse.ch/ioc/858742/

Intelligence


File Origin
# of uploads :
1
# of downloads :
256
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-vm evasive obfuscated
Result
Threat name:
NetWire, VjW0rm
Detection:
malicious
Classification:
troj.spyw.expl.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Benign windows process drops PE files
C2 URLs / IPs found in malware configuration
Contains functionality to steal Chrome passwords or cookies
Contains functionality to steal Internet Explorer form passwords
Creates multiple autostart registry keys
Drops script or batch files to the startup folder
Found evasive API chain (may stop execution after checking mutex)
Found stalling execution ending in API Sleep call
JavaScript source code contains functionality to generate code involving a shell, file or stream
JScript performs obfuscated calls to suspicious functions
Machine Learning detection for dropped file
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for domain / URL
Potential obfuscated javascript found
Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes)
Sigma detected: Drops script at startup location
Sigma detected: NetWire
Sigma detected: VjW0rm
Snort IDS alert for network traffic
System process connects to network (likely due to code injection or exploit)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Uses dynamic DNS services
Uses known network protocols on non-standard ports
Wscript called in batch mode (surpress errors)
Yara detected NetWire RAT
Yara detected VjW0rm
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 713475 Sample: Details.js Startdate: 30/09/2022 Architecture: WINDOWS Score: 100 90 Snort IDS alert for network traffic 2->90 92 Multi AV Scanner detection for domain / URL 2->92 94 Malicious sample detected (through community Yara rule) 2->94 96 12 other signatures 2->96 8 wscript.exe 5 16 2->8         started        13 wscript.exe 13 2->13         started        15 wscript.exe 13 2->15         started        17 5 other processes 2->17 process3 dnsIp4 80 kingshakes.ddns.net 79.134.225.76, 49707, 49710, 49715 FINK-TELECOM-SERVICESCH Switzerland 8->80 60 C:\Users\user\...\Details.js:Zone.Identifier, ASCII 8->60 dropped 62 C:\Users\user\AppData\Roaming\...\Details.js, ASCII 8->62 dropped 64 C:\Users\user\AppData\Roaming\FzZIQcZdse.js, ASCII 8->64 dropped 66 C:\Users\user\AppData\Local\...\035LPQW0KQ.js, ASCII 8->66 dropped 110 System process connects to network (likely due to code injection or exploit) 8->110 112 Benign windows process drops PE files 8->112 114 JScript performs obfuscated calls to suspicious functions 8->114 120 2 other signatures 8->120 19 wscript.exe 3 8->19         started        23 wscript.exe 13 8->23         started        68 C:\Users\user\AppData\Local\...\K8WHTBNMHZ.js, ASCII 13->68 dropped 116 Creates multiple autostart registry keys 13->116 118 Wscript called in batch mode (surpress errors) 13->118 26 wscript.exe 13->26         started        28 wscript.exe 13->28         started        30 wscript.exe 15->30         started        82 javaautorun.duia.ro 17->82 84 javaautorun.duia.ro 17->84 86 192.168.2.1 unknown unknown 17->86 32 wscript.exe 17->32         started        file5 signatures6 process7 dnsIp8 54 C:\Users\user\AppData\Roaming\Host.exe, PE32 19->54 dropped 56 C:\Users\user\AppData\Roaming\pExBarjhLo.js, ASCII 19->56 dropped 108 Wscript called in batch mode (surpress errors) 19->108 34 Host.exe 19->34         started        38 wscript.exe 19->38         started        78 javaautorun.duia.ro 95.142.119.7, 5465 ASDETUKhttpwwwheficedcomGB Czech Republic 23->78 58 C:\Users\user\AppData\...\FzZIQcZdse.js, ASCII 23->58 dropped 41 wscript.exe 26->41         started        43 Host.exe 26->43         started        file9 signatures10 process11 dnsIp12 50 C:\Users\user\AppData\Roaming\...\Update.exe, PE32 34->50 dropped 98 Antivirus detection for dropped file 34->98 100 Found evasive API chain (may stop execution after checking mutex) 34->100 102 Machine Learning detection for dropped file 34->102 106 2 other signatures 34->106 45 Update.exe 34->45         started        74 javaautorun.duia.ro 38->74 52 C:\Users\user\AppData\...\pExBarjhLo.js, ASCII 38->52 dropped 76 javaautorun.duia.ro 41->76 104 System process connects to network (likely due to code injection or exploit) 41->104 file13 signatures14 process15 dnsIp16 88 kingshakes.ddns.net 45->88 70 C:\Users\user\AppData\Roaming\...\sqlite3.dll, PE32 45->70 dropped 72 C:\Users\user\AppData\Local\...\LoginDataCopy, SQLite 45->72 dropped 122 Antivirus detection for dropped file 45->122 124 Found evasive API chain (may stop execution after checking mutex) 45->124 126 Tries to steal Mail credentials (via file / registry access) 45->126 128 6 other signatures 45->128 file17 signatures18
Threat name:
Script.Worm.Heuristic
Status:
Malicious
First seen:
2022-09-30 13:41:08 UTC
File Type:
Text (JavaScript)
AV detection:
6 of 25 (24.00%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:vjw0rm persistence trojan worm
Behaviour
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Adds Run key to start application
Checks computer location settings
Drops startup file
Blocklisted process makes network request
Vjw0rm
Malware Config
C2 Extraction:
http://kingshakes.ddns.net:6161
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_obfuscated_JS_obfuscatorio
Author:@imp0rtp3
Description:Detect JS obfuscation done by the js obfuscator (often malicious)
Reference:https://obfuscator.io

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments