🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b4489a7f0467bee2782b5e5cf74763d0c05148a9044092eb79aba7c588f35f99. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Vjw0rm


Vendor detections: 6


Intelligence 6 IOCs 1 YARA File information Comments

SHA256 hash: b4489a7f0467bee2782b5e5cf74763d0c05148a9044092eb79aba7c588f35f99
SHA3-384 hash: 90463e98852d5fa16fbae0774c748320142f64a862207c40371cccfb5a49d170f0461a7d6ec5cf309f6bee2b642eb5a9
SHA1 hash: 49fea89d7fc9f8be3afa2fd1b0ae9b6075c0acbf
MD5 hash: 1abbd5432118e4de7c696d5d43a7449f
humanhash: chicken-gee-fourteen-august
File name:NS882992019101.vbs
Download: download sample
Signature Vjw0rm
File size:13'967 bytes
First seen:2021-08-24 18:22:14 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 48:+OmYGJ08nH0Jn607W+CI0nJs56UbMH0a8y7j02J1mYGJ08nH0Jn607W+CI0nJu5O:B2aQxA4AeizBSF9MHlsTA
TLSH T129521731B55E7C95E6708B8A4F31C817E70E61565D78A807CCA23C0A0D732CE2EAD15F
Reporter abuse_ch
Tags:vbs vjw0rm


Avatar
abuse_ch
Vjw0rm C2:
http://serv01.nerdpol.ovh:7501/Vre

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
http://serv01.nerdpol.ovh:7501/Vre https://threatfox.abuse.ch/ioc/193816/

Intelligence


File Origin
# of uploads :
1
# of downloads :
158
Origin country :
n/a
Vendor Threat Intelligence
Result
Threat name:
Detection:
malicious
Classification:
troj.spyw.expl.evad
Score:
100 / 100
Signature
.NET source code references suspicious native API functions
Antivirus detection for dropped file
Bypasses PowerShell execution policy
C2 URLs / IPs found in malware configuration
Compiles code for process injection (via .Net compiler)
Deletes itself after installation
Drops VBS files to the startup folder
Found malware configuration
Hides that the sample has been downloaded from the Internet (zone.identifier)
Injects a PE file into a foreign processes
Installs a global keyboard hook
Malicious sample detected (through community Yara rule)
May check the online IP address of the machine
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Sigma detected: Drops script at startup location
Sigma detected: PowerShell DownloadFile
Sigma detected: Suspicious Csc.exe Source File Folder
Sigma detected: Suspicious Process Start Without DLL
Sigma detected: Suspicious Script Execution From Temp Folder
Suspicious powershell command line found
Tries to download and execute files (via powershell)
Uses known network protocols on non-standard ports
Uses ping.exe to check the status of other devices and networks
Uses ping.exe to sleep
VBScript performs obfuscated calls to suspicious functions
Writes to foreign memory regions
Wscript starts Powershell (via cmd or directly)
Yara detected AntiVM3
Yara detected Quasar RAT
Yara detected RUNPE
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 470953 Sample: NS882992019101.vbs Startdate: 24/08/2021 Architecture: WINDOWS Score: 100 111 Found malware configuration 2->111 113 Malicious sample detected (through community Yara rule) 2->113 115 Antivirus detection for dropped file 2->115 117 11 other signatures 2->117 11 wscript.exe 1 2->11         started        14 wscript.exe 2->14         started        17 wscript.exe 2->17         started        19 wscript.exe 1 2->19         started        process3 dnsIp4 141 VBScript performs obfuscated calls to suspicious functions 11->141 143 Suspicious powershell command line found 11->143 145 Wscript starts Powershell (via cmd or directly) 11->145 147 Tries to download and execute files (via powershell) 11->147 21 powershell.exe 14 19 11->21         started        109 192.168.2.1 unknown unknown 14->109 26 powershell.exe 14->26         started        28 powershell.exe 17->28         started        30 powershell.exe 20 19->30         started        signatures5 process6 dnsIp7 101 7501.nerdpol.ovh 185.81.157.16, 49711, 80 INU-ASFR France 21->101 91 C:\Users\Public\fr.PS1, awk 21->91 dropped 129 Suspicious powershell command line found 21->129 131 Drops VBS files to the startup folder 21->131 133 Bypasses PowerShell execution policy 21->133 135 Compiles code for process injection (via .Net compiler) 21->135 32 powershell.exe 25 21->32         started        37 conhost.exe 21->37         started        93 C:\Users\user\AppData\...\SystemLogin34.vbs, ASCII 26->93 dropped 95 C:\Users\user\AppData\Local\...\qu3p0aha.0.cs, C++ 26->95 dropped 137 Writes to foreign memory regions 26->137 139 Injects a PE file into a foreign processes 26->139 39 csc.exe 26->39         started        41 conhost.exe 26->41         started        43 RegAsm.exe 26->43         started        45 csc.exe 28->45         started        47 conhost.exe 28->47         started        49 RegAsm.exe 28->49         started        103 serv01.nerdpol.ovh 30->103 97 C:\Users\user\...\Windows10DecemberUpdate.vbs, ASCII 30->97 dropped 51 conhost.exe 30->51         started        file8 signatures9 process10 dnsIp11 99 serv01.nerdpol.ovh 185.81.157.187, 49712, 49713, 49716 INU-ASFR France 32->99 79 C:\Users\user\AppData\...\WinLOGON.vbs, ASCII 32->79 dropped 81 C:\...\9ef71ada7e9a404b8f7102ee06cfd6b5.PS1, ASCII 32->81 dropped 119 Suspicious powershell command line found 32->119 53 powershell.exe 20 32->53         started        83 C:\Users\user\AppData\Local\...\qu3p0aha.dll, PE32 39->83 dropped 57 cvtres.exe 39->57         started        85 C:\Users\user\AppData\Local\...\ymljvjas.dll, PE32 45->85 dropped 59 cvtres.exe 45->59         started        file12 signatures13 process14 file15 89 C:\Users\user\AppData\...\uo2iugfg.cmdline, UTF-8 53->89 dropped 125 Writes to foreign memory regions 53->125 127 Injects a PE file into a foreign processes 53->127 61 RegAsm.exe 53->61         started        65 csc.exe 3 53->65         started        signatures16 process17 dnsIp18 105 185.81.157.149, 49738, 7150 INU-ASFR France 61->105 107 ip-api.com 208.95.112.1, 49737, 80 TUT-ASUS United States 61->107 149 May check the online IP address of the machine 61->149 151 Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines) 61->151 153 Deletes itself after installation 61->153 155 2 other signatures 61->155 68 cmd.exe 61->68         started        87 C:\Users\user\AppData\Local\...\uo2iugfg.dll, PE32 65->87 dropped 71 cvtres.exe 65->71         started        file19 signatures20 process21 signatures22 121 Uses ping.exe to sleep 68->121 123 Uses ping.exe to check the status of other devices and networks 68->123 73 conhost.exe 68->73         started        75 chcp.com 68->75         started        77 PING.EXE 68->77         started        process23
Threat name:
Script.Downloader.Heuristic
Status:
Malicious
First seen:
2021-08-24 18:23:10 UTC
AV detection:
3 of 46 (6.52%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:vjw0rm trojan worm
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Drops startup file
Blocklisted process makes network request
Vjw0rm
Malware Config
Dropper Extraction:
http://7501.nerdpol.ovh/7501/fr.txt
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments