🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d342cec59ebc05ff56c40ee2ffb1024883d89532f32ee3f2b53cc1ca57eb5259. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Vjw0rm


Vendor detections: 6


Intelligence 6 IOCs 2 YARA File information Comments

SHA256 hash: d342cec59ebc05ff56c40ee2ffb1024883d89532f32ee3f2b53cc1ca57eb5259
SHA3-384 hash: 78848dc348d6bb11a5b9a03984c2796d1ccdce8b07cc8e5932b8a2f0ae5868ebc482382b28d09fc80556baafd5a64dab
SHA1 hash: 42f52462f338dce7a6e3f52a8c4b8b5d18297bc8
MD5 hash: 93b507e5fe85f2e4d84374cd4c1424cd
humanhash: fanta-lion-december-double
File name:proof of payment.001
Download: download sample
Signature Vjw0rm
File size:14'555 bytes
First seen:2022-10-24 12:32:03 UTC
Last seen:2022-10-24 12:33:21 UTC
File type: rar
MIME type:application/x-rar
ssdeep 384:RvHlFIAFNVZirtoSeGj5wTXzCg9VLHOxUx7mmiQyAuRP5665P2:1lNFweGlw3VL/7NB1uRh6W+
TLSH T10B62C071E039013D84745B1BDD383214734866F64169832BB13B47D3BDDA5B987B2949
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Reporter cocaman
Tags:001 payment rar vjw0rm


Avatar
cocaman
Malicious email (T1566.001)
From: ""Euro Exchange" <info@euro.co.uk>" (likely spoofed)
Received: "from slot0.oghuy.us (slot0.oghuy.us [142.11.227.35]) "
Date: "Mon, 24 Oct 2022 05:31:17 -0700"
Subject: "Payment Slip"
Attachment: "proof of payment.001"

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
http://chuks.wikaba.com:6424/is-ready https://threatfox.abuse.ch/ioc/916372/
109.206.243.106:6424 https://threatfox.abuse.ch/ioc/916373/

Intelligence


File Origin
# of uploads :
2
# of downloads :
144
Origin country :
n/a
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:proof of payment.js
File size:40'067 bytes
SHA256 hash: c91bae3e00eabcee11b278419c503cbb28f94372f349ff56d0d04207d5f1e7fe
MD5 hash: 5b6e9a548c15dc32988b91c6ca5ec2df
MIME type:text/plain
Signature Vjw0rm
Vendor Threat Intelligence
Threat name:
Script-JS.Trojan.Vjw0rm
Status:
Malicious
First seen:
2022-10-24 15:14:07 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
14 of 42 (33.33%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:vjw0rm family:wshrat persistence trojan worm
Behaviour
Script User-Agent
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Adds Run key to start application
Checks computer location settings
Drops startup file
Blocklisted process makes network request
Vjw0rm
WSHRAT
Malware Config
C2 Extraction:
http://chuks.wikaba.com:6424
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Vjw0rm

rar d342cec59ebc05ff56c40ee2ffb1024883d89532f32ee3f2b53cc1ca57eb5259

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
Vjw0rm

Comments