🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ec6becf63e601f9160ed615d0d75c877a9cbcb52caa6a7bd1e1542b30d9b3db5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Vjw0rm


Vendor detections: 9


Intelligence 9 IOCs 1 YARA File information Comments

SHA256 hash: ec6becf63e601f9160ed615d0d75c877a9cbcb52caa6a7bd1e1542b30d9b3db5
SHA3-384 hash: 36a3a4d0f6bfe8a19aa1883a89bd9aa3f34b32ef06aba22b6095bc74b34b0e2912b3ecbc36a399c0ee07f998deaa0b37
SHA1 hash: 2e94882ee4dffe33bf78365bf1840bc7e2e7e922
MD5 hash: a54f1e6588db5af2fbb4372881301a80
humanhash: fourteen-lamp-mississippi-two
File name:ORDER-24110394.PDF.js
Download: download sample
Signature Vjw0rm
File size:7'879 bytes
First seen:2024-11-04 01:15:27 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 48:RkEDv6b+vEalLVtkE0tHNNk/NWuFkkkkE7fLv6b+vEazrwEDtfUFvBiv/o1jyLEZ:JJ3IeeveY+t
TLSH T12FF1C90AB3CC5E2ADEF061DD4BB9294BD68E0D193124B3F68E5FFAC11B446BD3964904
Magika javascript
Reporter abuse_ch
Tags:js vjw0rm


Avatar
abuse_ch
Vjw0rm C2:
188.126.90.66:7045

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
188.126.90.66:7045 https://threatfox.abuse.ch/ioc/1340792/

Intelligence


File Origin
# of uploads :
1
# of downloads :
9'950
Origin country :
NL NL
Vendor Threat Intelligence
Verdict:
Malicious
Score:
90.2%
Tags:
autorun houdini dunihi worm
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
masquerade
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
100 / 100
Signature
JavaScript source code contains functionality to generate code involving a shell, file or stream
JavaScript source code contains functionality to generate code involving HTTP requests or file downloads
JScript performs obfuscated calls to suspicious functions
Multi AV Scanner detection for submitted file
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Suspicious Parent Double Extension File Execution
Sigma detected: Suspicious Script Execution From Temp Folder
Sigma detected: WScript or CScript Dropper
Sigma detected: WScript or CScript Dropper - File
System process connects to network (likely due to code injection or exploit)
Uses an obfuscated file name to hide its real file extension (double extension)
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Windows Shell Script Host drops VBS files
Behaviour
Behavior Graph:
Threat name:
Script-JS.Trojan.Cryxos
Status:
Malicious
First seen:
2024-11-04 01:16:10 UTC
File Type:
Text (JavaScript)
AV detection:
6 of 38 (15.79%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
Checks computer location settings
Blocklisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments