🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f22945e84a4a8dc6ec66734fe9028884f8929fd6a862b1f65eb6de5d96ba8119. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Vjw0rm


Vendor detections: 5


Intelligence 5 IOCs 1 YARA File information Comments

SHA256 hash: f22945e84a4a8dc6ec66734fe9028884f8929fd6a862b1f65eb6de5d96ba8119
SHA3-384 hash: 20d10ba8b65f58adca529fc3b9c0cd80310edceb26f0ca62ee913d2d2a6294292ef86558ff9623d7b67a86fbee0967e2
SHA1 hash: bd13e8fba4a7d087df8cdc51da3d1f185c25fe40
MD5 hash: 9962eb28b9bc0bbc9352716673d2475b
humanhash: eleven-fruit-pennsylvania-three
File name:ColisFR512562J01201.js
Download: download sample
Signature Vjw0rm
File size:343'832 bytes
First seen:2021-06-18 05:16:10 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 768:inaFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFTKu4crJd01LdUy1t:inL9S+BZ1XsOyolaRw6iVP9
TLSH 9174DB458ED04C1BB7B1C20794E90D52CD1365F2CB6EB54BD0C5D6BEBE9A223730BA1A
Reporter abuse_ch
Tags:js vjw0rm


Avatar
abuse_ch
Vjw0rm C2:
http://newstokora.xyz:8799/Vre

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
http://newstokora.xyz:8799/Vre https://threatfox.abuse.ch/ioc/136036/

Intelligence


File Origin
# of uploads :
1
# of downloads :
142
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Script.Trojan.Heuristic
Status:
Malicious
First seen:
2021-06-18 05:17:08 UTC
AV detection:
2 of 46 (4.35%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:vjw0rm trojan worm
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Drops startup file
Blocklisted process makes network request
Vjw0rm
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments