🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 be819044d31095c9cd4b85d251e777c13843a94af15da86a1db0dff7bad2eda5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Vjw0rm


Vendor detections: 6


Intelligence 6 IOCs 1 YARA File information Comments

SHA256 hash: be819044d31095c9cd4b85d251e777c13843a94af15da86a1db0dff7bad2eda5
SHA3-384 hash: b7a34c240bb3953eb3eccdc2817acea8d46f71582e3c4690a41b9cd33e385c233f44c9b34448487581d8031915b7660a
SHA1 hash: 17c7832f8c12ccdd34a6b5a21a696babe062993b
MD5 hash: 1acdbb2c929e1d4ef0c3faaff2c81a62
humanhash: lactose-speaker-winner-orange
File name:InfoReleveID002155207.vbs
Download: download sample
Signature Vjw0rm
File size:102'401 bytes
First seen:2022-05-10 05:11:30 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 1536:zjvKiICrU81VUr1WU5yDYU1rMX7yDYU1rXsXVU28u5BUSrXiICrU81VUr1WU5yDe:G
TLSH T136A3D8F82D3E4169E5EA14F7CECE76586622FE43C2C354AC5C54CEE1266E328D2C7618
Reporter abuse_ch
Tags:vbs vjw0rm


Avatar
abuse_ch
Vjw0rm C2:
http://185.81.157.210:3681/Vre

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
http://185.81.157.210:3681/Vre https://threatfox.abuse.ch/ioc/549290/

Intelligence


File Origin
# of uploads :
1
# of downloads :
244
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Result
Threat name:
Unknown
Detection:
malicious
Classification:
troj.expl.evad
Score:
92 / 100
Signature
Antivirus detection for dropped file
Drops VBS files to the startup folder
Malicious sample detected (through community Yara rule)
Sigma detected: Drops script at startup location
Snort IDS alert for network traffic
System process connects to network (likely due to code injection or exploit)
Uses known network protocols on non-standard ports
Wscript starts Powershell (via cmd or directly)
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 623194 Sample: InfoReleveID002155207.vbs Startdate: 10/05/2022 Architecture: WINDOWS Score: 92 48 Snort IDS alert for network traffic 2->48 50 Malicious sample detected (through community Yara rule) 2->50 52 Antivirus detection for dropped file 2->52 54 2 other signatures 2->54 7 wscript.exe 3 1 2->7         started        11 wscript.exe 1 2->11         started        13 wscript.exe 1 2->13         started        process3 dnsIp4 40 SQL8003.site4now.net 199.102.48.248, 1433, 49718 ZCOLO-LAS01US United States 7->40 56 System process connects to network (likely due to code injection or exploit) 7->56 58 Wscript starts Powershell (via cmd or directly) 7->58 15 powershell.exe 14 19 7->15         started        20 powershell.exe 11->20         started        22 powershell.exe 6 13->22         started        signatures5 process6 dnsIp7 44 2.56.57.82, 49740, 80 GBTCLOUDUS Netherlands 15->44 34 C:\Users\Public\SystemLogin.PS1, UTF-8 15->34 dropped 46 Drops VBS files to the startup folder 15->46 24 powershell.exe 24 15->24         started        28 conhost.exe 15->28         started        30 conhost.exe 20->30         started        32 conhost.exe 22->32         started        file8 signatures9 process10 dnsIp11 42 185.81.157.210, 3681, 49741, 49742 INU-ASFR France 24->42 36 C:\Users\...behaviorgraphoogleChromeUpdateHandlerx64.vbs, ASCII 24->36 dropped 38 C:\Users\...behaviorgraphoogleChromeUpdateHandler.vbs, ASCII 24->38 dropped file12
Threat name:
Script.Trojan.Heuristic
Status:
Malicious
First seen:
2022-05-10 05:12:06 UTC
File Type:
Text (VBS)
AV detection:
8 of 26 (30.77%)
Threat level:
  2/5
Verdict:
unknown
Result
Malware family:
n/a
Score:
  10/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Drops startup file
Blocklisted process makes network request
Malware Config
Dropper Extraction:
http://2.56.57.82/1/SystemLogin.txt
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments