🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://loadcash.duckdns.org:7778.

Database Entry


IOC ID:239374
IOC: http://loadcash.duckdns.org:7778
IOC Type :url
Threat Type :botnet_cc
Malware: Vjw0rm
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS401116 NYBULA
Country:- US
First seen:2021-10-28 21:36:04 UTC
Last seen:never
UUID:0d5f7ce0-3837-11ec-8ab6-42010aa4000a
Reporter AndreGironda
Reward 5 credits from ThreatFox
Tags:Vjw0rm
Reference: https://tria.ge/211028-1b3w4accb9

Avatar
AndreGironda
MITRE T1566.001
Date: Thu, 28 Oct 2021 16:30-17:00 -0400 (EDT)
Received: from nmtao101.oxsus-vadesecure.net (51.81.61.64)
From: ups-com <admin@frmenterprises.com>
Message-ID: <1635107968.33198.1635453584758@webmail-oxcs.networksolutionsemail.com>
Subject: your parcel delivery
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----=_Part_33196_1274488656.1635453584756"
X-Priority: 3
Importance: Normal
X-Mailer: Open-Xchange Mailer v7.10.5-Rev22
X-Originating-IP: 20.109.189.14
X-Originating-Client: open-xchange-appsuite
To: Undisclosed recipients:;
Return-Path: admin@frmenterprises.com
Attachment Name: receipt.img
Attachment SHA256: 11bb4657fed6dc30a08e4c5e7d40affbf48e3c3e5a38e662b40a431a176a9337
Contained JavaScript Dropper Name: receipt.js
JS Dropper SHA256: 12adc7362259c2e56998f6a108861b6c128c84af9136187c750c3a34a0ef55ad
Unpacked VjW0rm JS Dropper SHA256: e5654e90cc350e02af6ac85173ce16a9228acc1720685b9ef47e84a58e611541