🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://loadcash.duckdns.org:7779/Vre.

Database Entry


IOC ID:236010
IOC: http://loadcash.duckdns.org:7779/Vre
IOC Type :url
Threat Type :botnet_cc
Malware: Vjw0rm
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS401116 NYBULA
Country:- US
First seen:2021-10-21 00:56:25 UTC
Last seen:never
UUID:b7a5af1b-3209-11ec-a35f-42010aa4000a
Reporter AndreGironda
Reward 5 credits from ThreatFox
Tags:Vjw0rm
Reference: https://tria.ge/211021-a8cs3ahfh7

Avatar
AndreGironda
MITRE T1566.001
Date: Wed, 20 Oct 2021 19:00-19:30 -0500
Received: from sonic316-12.consmr.mail.bf2.yahoo.com (74.6.130.122)
Content-Type: multipart/alternative; boundary=Apple-Mail-5A5847B2-D9C6-40E2-BC1C-B2D6D4DB34A3
Content-Transfer-Encoding: 7bit
From: DIANA THOMAS <iamdjst@aol.com>
Mime-Version: 1.0 (1.0)
Subject: Fwd: parcel delivery!!!
Message-Id: <2F9554DC-44E6-4A7B-AD52-4F6B84ACEA9C@aol.com>
References: <202110201735.19KHZ6tL011002@mail03.lsn.net>
X-Mailer: iPad Mail (18H17)
Content-Length: 1685571
Return-Path: iamdjst@aol.com
Attachment Name: eReceipt.img
Attachment SHA256: 005c4dc673face9b4900d1d489598c90867658b264b0a8fffb0b0d22ad289927
Contained JavaScript Dropper Name: eReceipt#.js
JS Dropper SHA256: 45e73465c8aece762bbc13f9a84667a603edb1824a3ab6612c440eda89120678
VjW0rm JS Dropper SHA256: 3de222c8faa973c5eeaf92c222b505700c626e80a439c3621a1c0c637babdf57
Unpacked Vjw0rm JS SHA256: 975960b6b7cd3d431a3d9ddf18755d073b13f88ad283ebfbe4105c5319d09a9a