ThreatFox IOC Database
You are viewing the ThreatFox database entry for url http://purecry54.duckdns.org:7779/Vre.
Database Entry
This IOC expired
This IOC is an old IOC and hence has expired on 2026-09-15 10:39:25 UTC. We therefore refrain from exporting it into our datasets. As a result, this database entry is purely informational and has no impact.
| IOC ID: | 241651 |
|---|---|
| IOC: | http://purecry54.duckdns.org:7779/Vre |
| IOC Type : | url |
| Threat Type : | botnet_cc |
| Malware: | Vjw0rm |
| Confidence Level : | Confidence level is high (100%) |
| Is compromised? : | False |
| ASN: | AS27323 SERVERSTADIUM |
| Country: | US |
| First seen: | 2021-11-02 21:05:55 UTC |
| Last seen: | never |
| UUID: | ab9f8239-3c20-11ec-8ab6-42010aa4000a |
| Reporter | |
| Reward | 5 credits from ThreatFox |
| Tags: | Vjw0rm |
| Reference: | https://tria.ge/211102-znybpscfe |
AndreGironda
MITRE T1566.001Date: Tue, 02 Nov 2021 17:00-17:30 +0000
Received: from WIN-6KR8LF0SF1H.us-east-2.compute.internal (ec2-13-59-5-99.us-east-2.compute.amazonaws.com [13.59.5.99])
Content-Type: multipart/mixed; boundary="===============1822163571=="
MIME-Version: 1.0
Subject: Your Parcel
To: Recipients <emma@thebrenners.co.uk>
From: "UPS Choice's." <emma@thebrenners.co.uk>
Message-ID: <296802b3-aa98-4abd-9de4-328024f64219@DM6NAM11FT049.eop-nam11.prod.protection.outlook.com>
Return-Path: emma@thebrenners.co.uk
Attachment Name: eReceipt.img
Attachment SHA256: 42f30e00956ce756a1d6cdc9327b8679a97ca09732598900d523b36a6b522a3d
JavaScript Dropper Name: eReceipt#.js
VjW0rm JS Dropper SHA256: 8c486c8c4429c6acedd923708a36c16322ab7aa0c0c828b512dbd970d1818399
Malware Samples
The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).
| Time stamp (UTC) | SHA256 hash | Bazaar |
|---|---|---|
| 2021-11-03 02:15:57 | 8c486c8c4429c6acedd923708a36c16322ab7aa0c0c828b512dbd970d1818399 |
US