ThreatFox IOC Database
You are viewing the ThreatFox database entry for url http://dingspread.duckdns.org:6130.
Database Entry
This IOC expired
This IOC is an old IOC and hence has expired on 2026-09-15 10:39:25 UTC. We therefore refrain from exporting it into our datasets. As a result, this database entry is purely informational and has no impact.
| IOC ID: | 239303 |
|---|---|
| IOC: | http://dingspread.duckdns.org:6130 |
| IOC Type : | url |
| Threat Type : | botnet_cc |
| Malware: | Vjw0rm |
| Confidence Level : | Confidence level is high (100%) |
| Is compromised? : | False |
| ASN: | AS27323 SERVERSTADIUM |
| Country: | US |
| First seen: | 2021-10-28 14:57:48 UTC |
| Last seen: | never |
| UUID: | 6a754aa8-37ff-11ec-8ab6-42010aa4000a |
| Reporter | |
| Reward | 5 credits from ThreatFox |
| Tags: | Vjw0rm |
| Reference: | https://tria.ge/211028-rkpldsbgb3 |
AndreGironda
MITRE T1566.001Date: Thu, 28 Oct 2021 13:30-14:00 -0000
Received: from smtp107.iad3a.emailsrvr.com (173.203.187.107)
From: "Roger"<rugarc@westelcom.com>
Subject: Invoice Order #WR00N450JA Attached
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----=_NextPart_000_00AA_01C2A9A6.27C51D98"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
X-Classification-ID: 88deab88-98a0-4020-b9e6-71e2335c4cd3-1-1
Message-ID: <76244189-09bc-42c7-87be-f2101c16898e@CO1NAM11FT047.eop-nam11.prod.protection.outlook.com>
To: Undisclosed recipients:;
Return-Path: rugarc@westelcom.com
Attachment 1 Name: #0011.iso
Attachment 1 SHA256: c5adbc699a89e656e1f0cdbaec8e25651202d8052ded04360f270fc8fbb6edfd
Attachment 2 Name: #0012DH889032.ISO
Attachment 2 SHA256: 3e55c65e123a69e7a14e5c02658d402f099f2ef33aef7227deecfc7d658b07a5
Contained 1 JavaScript Dropper Name: #0011.js
VjW0rm JS Dropper SHA256: c40b980e8d0447cc55bffa7c5f5af8f7dba5d3ff411edfc028836c7a631af874
UDF_Encapsulated_Executable 2 VBScript Name: #0012HSJMS.vbs
VBScript SHA256: 5d284dd34b832bb18e1eb94d31e7795c305211e4d4f53160a592fddfa9944835
VBScript Stage URL: hXXp://52[.]27.15.250/A/SJJS[.]txt
US