ThreatFox IOC Database
You are viewing the ThreatFox database entry for url http://loadcash.duckdns.org:7778.
Database Entry
This IOC expired
This IOC is an old IOC and hence has expired on 2026-09-15 10:39:25 UTC. We therefore refrain from exporting it into our datasets. As a result, this database entry is purely informational and has no impact.
| IOC ID: | 239374 |
|---|---|
| IOC: | http://loadcash.duckdns.org:7778 |
| IOC Type : | url |
| Threat Type : | botnet_cc |
| Malware: | Vjw0rm |
| Confidence Level : | Confidence level is high (100%) |
| Is compromised? : | False |
| ASN: | AS401116 NYBULA |
| Country: | US |
| First seen: | 2021-10-28 21:36:04 UTC |
| Last seen: | never |
| UUID: | 0d5f7ce0-3837-11ec-8ab6-42010aa4000a |
| Reporter | |
| Reward | 5 credits from ThreatFox |
| Tags: | Vjw0rm |
| Reference: | https://tria.ge/211028-1b3w4accb9 |
AndreGironda
MITRE T1566.001Date: Thu, 28 Oct 2021 16:30-17:00 -0400 (EDT)
Received: from nmtao101.oxsus-vadesecure.net (51.81.61.64)
From: ups-com <admin@frmenterprises.com>
Message-ID: <1635107968.33198.1635453584758@webmail-oxcs.networksolutionsemail.com>
Subject: your parcel delivery
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----=_Part_33196_1274488656.1635453584756"
X-Priority: 3
Importance: Normal
X-Mailer: Open-Xchange Mailer v7.10.5-Rev22
X-Originating-IP: 20.109.189.14
X-Originating-Client: open-xchange-appsuite
To: Undisclosed recipients:;
Return-Path: admin@frmenterprises.com
Attachment Name: receipt.img
Attachment SHA256: 11bb4657fed6dc30a08e4c5e7d40affbf48e3c3e5a38e662b40a431a176a9337
Contained JavaScript Dropper Name: receipt.js
JS Dropper SHA256: 12adc7362259c2e56998f6a108861b6c128c84af9136187c750c3a34a0ef55ad
Unpacked VjW0rm JS Dropper SHA256: e5654e90cc350e02af6ac85173ce16a9228acc1720685b9ef47e84a58e611541
US