MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ae33e9f2e18d4fdd25db5bc30b8b8bdd63b53794e225dbe818ebe65a29b0dc95. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Vjw0rm


Vendor detections: 5


Intelligence 5 IOCs 1 YARA File information Comments

SHA256 hash: ae33e9f2e18d4fdd25db5bc30b8b8bdd63b53794e225dbe818ebe65a29b0dc95
SHA3-384 hash: cfd32e19470111c2229a5ae52a8eb4caec7ade562a42279f47faab69267fb7c34ea7b872df20a6cd688209180604227d
SHA1 hash: 051c9770aebcc850ae09baa6a223848a7aa3f289
MD5 hash: d82b9d7af67f2ade0c11bfe6bfd69544
humanhash: leopard-pizza-maine-november
File name:Orderlistxlsx.jar
Download: download sample
Signature Vjw0rm
File size:132'818 bytes
First seen:2021-08-30 07:42:56 UTC
Last seen:Never
File type:Java file jar
MIME type:application/zip
ssdeep 3072:PdaZuzVCyUNstfAQyHuAYWgPNr6K5V3I/Iy7+itIlhGDbmC:PNIsNyH/LgPNrPH4/I7jhGDb
TLSH T1BFD312652CFD7CCBDCA32734DA87A1857B39B11AA256370A86E1ECF4D1A4D86304081F
Reporter abuse_ch
Tags:jar vjw0rm


Avatar
abuse_ch
Vjw0rm C2:
144.168.231.6:7777

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
144.168.231.6:7777 https://threatfox.abuse.ch/ioc/202257/

Intelligence


File Origin
# of uploads :
1
# of downloads :
144
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
Orderlistxlsx.jar
Verdict:
No threats detected
Analysis date:
2021-08-30 07:51:25 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Threat name:
Detection:
malicious
Classification:
troj.expl.evad
Score:
100 / 100
Signature
Connects to many ports of the same IP (likely port scanning)
Creates multiple autostart registry keys
Drops script or batch files to the startup folder
Exploit detected, runtime environment dropped PE file
Exploit detected, runtime environment starts unknown processes
May check the online IP address of the machine
Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes)
Sigma detected: Drops script at startup location
Sigma detected: WScript or CScript Dropper
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
System process connects to network (likely due to code injection or exploit)
Uses dynamic DNS services
Uses schtasks.exe or at.exe to add and modify task schedules
Yara detected AllatoriJARObfuscator
Yara detected STRRAT
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 473785 Sample: Orderlistxlsx.jar Startdate: 30/08/2021 Architecture: WINDOWS Score: 100 81 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->81 83 Yara detected STRRAT 2->83 85 Sigma detected: Drops script at startup location 2->85 87 7 other signatures 2->87 11 cmd.exe 2 2->11         started        14 wscript.exe 2->14         started        18 wscript.exe 2->18         started        process3 dnsIp4 95 Uses schtasks.exe or at.exe to add and modify task schedules 11->95 20 java.exe 6 11->20         started        23 conhost.exe 11->23         started        69 javaslinns.duia.ro 14->69 61 C:\Users\user\AppData\...\DGjEIUIodz.js, ASCII 14->61 dropped 97 System process connects to network (likely due to code injection or exploit) 14->97 99 Drops script or batch files to the startup folder 14->99 101 Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes) 14->101 71 javaslinns.duia.ro 18->71 103 Creates multiple autostart registry keys 18->103 file5 signatures6 process7 file8 53 C:\Users\user\exohdopokf.js, ASCII 20->53 dropped 25 wscript.exe 3 3 20->25         started        28 icacls.exe 1 20->28         started        process9 signatures10 91 Drops script or batch files to the startup folder 25->91 93 Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes) 25->93 30 javaw.exe 26 25->30         started        33 wscript.exe 2 13 25->33         started        35 conhost.exe 28->35         started        process11 dnsIp12 73 github.com 140.82.121.4, 443, 49700 GITHUBUS United States 30->73 75 github-releases.githubusercontent.com 185.199.108.154, 443, 49704 FASTLYUS Netherlands 30->75 79 3 other IPs or domains 30->79 37 java.exe 2 21 30->37         started        77 javaslinns.duia.ro 79.134.225.10, 49699, 49707, 49713 FINK-TELECOM-SERVICESCH Switzerland 33->77 process13 file14 55 C:\Users\user\AppData\Roaming\wuvexrbg.txt, Zip 37->55 dropped 57 C:\Users\user\...\jna7713786579977797136.dll, PE32 37->57 dropped 89 Creates multiple autostart registry keys 37->89 41 java.exe 37->41         started        45 cmd.exe 37->45         started        47 conhost.exe 37->47         started        signatures15 process16 dnsIp17 63 ip-api.com 208.95.112.1, 49725, 80 TUT-ASUS United States 41->63 65 divineconnect.ddns.net 144.168.231.6, 49718, 49738, 7777 SERVER-MANIACA Canada 41->65 67 str-master.pw 41->67 59 C:\Users\user\...\jna7060391197161183290.dll, PE32 41->59 dropped 49 conhost.exe 41->49         started        51 conhost.exe 45->51         started        file18 process19
Threat name:
Archive-JAR.Trojan.AdWind
Status:
Malicious
First seen:
2021-08-30 07:43:04 UTC
AV detection:
10 of 46 (21.74%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments