🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://gg1592661.duckdns.org:7924/Vre.

Database Entry


IOC ID:236202
IOC: http://gg1592661.duckdns.org:7924/Vre
IOC Type :url
Threat Type :botnet_cc
Malware: Vjw0rm
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS30823 AUROLOGIC
Country:- DE
First seen:2021-10-21 15:47:11 UTC
Last seen:never
UUID:2775ec34-3286-11ec-a35f-42010aa4000a
Reporter AndreGironda
Reward 5 credits from ThreatFox
Tags:Vjw0rm
Reference: https://tria.ge/211021-s5kzdabdbp

Avatar
AndreGironda
MITRE T1566.001
Date: Thu, 21 Oct 2021 15:00-16:00 -0000
Received: from smtp66.iad3a.emailsrvr.com (173.203.187.66)
From: "Jame"<lyndacerickson@1791.com>
Subject: Your Order: #TROOS6G09
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----=_NextPart_000_00D1_01C2A9A6.3F8FC262"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
X-Classification-ID: 1bfc3667-7bed-4231-9e5e-606a7ac1bed7-1-1
Message-ID: <240b6081-e193-4f4f-ac30-8ef0a6327822@DM6NAM11FT038.eop-nam11.prod.protection.outlook.com>
To: Undisclosed recipients:;
Return-Path: lyndacerickson@1791.com
Attachment Name: TROOS_Invoice_Copy.iso
Attachment SHA256: 40e728f2b56b74a4591d01544389e5b15224626e6b3db43a0f1752d114e6c2c4
JavaScript Dropper Name: TROOS_Invoice_Copy.js
VjW0rm JS Dropper SHA256: 5d7a0823b291315c81e35ed0c7ca7c81c6595c7ca9e5ebf0f56993a02d77c1f2