ThreatFox IOC Database
You are viewing the ThreatFox database entry for url http://btime1624.duckdns.org:7923/Vre.
Database Entry
This IOC expired
This IOC is an old IOC and hence has expired on 2026-09-15 10:39:25 UTC. We therefore refrain from exporting it into our datasets. As a result, this database entry is purely informational and has no impact.
| IOC ID: | 235178 |
|---|---|
| IOC: | http://btime1624.duckdns.org:7923/Vre |
| IOC Type : | url |
| Threat Type : | botnet_cc |
| Malware: | Vjw0rm |
| Confidence Level : | Confidence level is high (100%) |
| Is compromised? : | False |
| ASN: | AS8075 MICROSOFT-CORP-MSN-AS-BLOCK |
| Country: | US |
| First seen: | 2021-10-18 15:16:49 UTC |
| Last seen: | never |
| UUID: | 6a689e8b-3026-11ec-a35f-42010aa4000a |
| Reporter | |
| Reward | 5 credits from ThreatFox |
| Tags: | Vjw0rm |
| Reference: | https://tria.ge/211018-r2xnbsefhq |
AndreGironda
MITRE T1566.001Date: Mon, 18 Oct 2021 14:30-15:00 -0000
Received: from smtp101.ord1d.emailsrvr.com (184.106.54.101)
X-Auth-ID: geri.young@valir.com
From: "Roger"<geri.young@valir.com>
Subject: Invoice Order #TOO89MOP Attached
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----=_NextPart_000_011D_01C2A9A6.57321332"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
X-Classification-ID: 1b12a5ba-c0d3-49b6-aed9-9d9708328347-1-1
Message-ID: <1a21f31c-b02a-4419-9a08-6049e76f02eb@CO1NAM11FT043.eop-nam11.prod.protection.outlook.com>
To: Undisclosed recipients:;
Return-Path: geri.young@valir.com
Attachment Name: TOO89_Payment_Invoice.iso
Attachment SHA256: 88d5612f38441b9fbccb9e2e43bba16291eea23e7d90bc7755920a0252369eff
UDF Encapsulated JavaScript Dropper Name: TOO89_Payment_Invoice.js
VjW0rm JS Dropper SHA256: 5518f5e20b27a4b10ebc7abce37c733ab532354b5db6aed7edf19c25caba2ff3
[info] IOC: The script read a registry key
[warn] Unknown registry key HKCU\vjw0rm!
[info] Copying C:Users\Sysop12\AppData\Roaming\Microsoft\Templates\0.2638666.jse to C:\Users\SYSOP1~1\AppData\Local\Temp\0.2638666.jse
[info] Setting registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run\6ID7YY2BDP to "C:\Users\SYSOP1~1\AppData\Local\Temp\0.2638666.jse" of type REG_SZ
[info] Executing TOO89_Payment_Invoice.js.1.results/9fdb53f7-67ff-4a72-a792-9bcc5a207cec in the WScript shell
[info] Script read environment variable computername
[info] Script read environment variable username
[info] Script tried to read information about operating system
[info] Header set for http://btime1624.duckdns.org:7923/Vre:
[info] POST http://btime1624.duckdns.org:7923/Vre
[info] IOC: The script fetched an URL.
"type": "UrlFetch", "method": "POST",
"url": "http://btime1624.duckdns.org:7923/Vre",
"User-Agent": "vjw0rm_B55B4A40\\USER-PC\\User\\Microsoft Windows 10 Enterprise\\undefined\\\\NO\\\\"
US