🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://purecry54.duckdns.org:7779/Vre.

Database Entry


IOC ID:241651
IOC: http://purecry54.duckdns.org:7779/Vre
IOC Type :url
Threat Type :botnet_cc
Malware: Vjw0rm
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS27323 SERVERSTADIUM
Country:- US
First seen:2021-11-02 21:05:55 UTC
Last seen:never
UUID:ab9f8239-3c20-11ec-8ab6-42010aa4000a
Reporter AndreGironda
Reward 5 credits from ThreatFox
Tags:Vjw0rm
Reference: https://tria.ge/211102-znybpscfe

Avatar
AndreGironda
MITRE T1566.001
Date: Tue, 02 Nov 2021 17:00-17:30 +0000
Received: from WIN-6KR8LF0SF1H.us-east-2.compute.internal (ec2-13-59-5-99.us-east-2.compute.amazonaws.com [13.59.5.99])
Content-Type: multipart/mixed; boundary="===============1822163571=="
MIME-Version: 1.0
Subject: Your Parcel
To: Recipients <emma@thebrenners.co.uk>
From: "UPS Choice's." <emma@thebrenners.co.uk>
Message-ID: <296802b3-aa98-4abd-9de4-328024f64219@DM6NAM11FT049.eop-nam11.prod.protection.outlook.com>
Return-Path: emma@thebrenners.co.uk
Attachment Name: eReceipt.img
Attachment SHA256: 42f30e00956ce756a1d6cdc9327b8679a97ca09732598900d523b36a6b522a3d
JavaScript Dropper Name: eReceipt#.js
VjW0rm JS Dropper SHA256: 8c486c8c4429c6acedd923708a36c16322ab7aa0c0c828b512dbd970d1818399

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2021-11-03 02:15:57 8c486c8c4429c6acedd923708a36c16322ab7aa0c0c828b512dbd970d1818399