ThreatFox IOC Database
You are viewing the ThreatFox database entry for url http://194.156.90.26:8012.
Database Entry
This IOC expired
This IOC is an old IOC and hence has expired on 2026-09-15 10:39:25 UTC. We therefore refrain from exporting it into our datasets. As a result, this database entry is purely informational and has no impact.
| IOC ID: | 244427 |
|---|---|
| IOC: | http://194.156.90.26:8012 |
| IOC Type : | url |
| Threat Type : | botnet_cc |
| Malware: | Vjw0rm |
| Confidence Level : | Confidence level is high (100%) |
| Is compromised? : | False |
| ASN: | AS30823 AUROLOGIC |
| Country: | DE |
| First seen: | 2021-11-05 17:47:41 UTC |
| Last seen: | never |
| UUID: | 7946fb8f-3e60-11ec-8ab6-42010aa4000a |
| Reporter | |
| Reward | 5 credits from ThreatFox |
| Tags: | Vjw0rm |
| Reference: | https://tria.ge/211105-sthd4scbc2 |
AndreGironda
MITRE T1566.001Date: Fri, 5 Nov 2021 07:00-07:30 -0700
Received: from smtp64.ord1c.emailsrvr.com (108.166.43.64)
X-Auth-ID: royaloak@ezmini.com
From: "Dabbie"<royaloak@ezmini.com>
Subject: Invoice Order #UE00S802H Attached
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----=_NextPart_000_012B_01C2A9A6.2E419494"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
X-Classification-ID: bf564ea3-1074-49b6-9248-7086613f0f8e-1-1
Message-ID: <00020d3e-b7e1-4538-9e3b-2dae2559864a@DM6NAM11FT049.eop-nam11.prod.protection.outlook.com>
To: Undisclosed recipients:;
Return-Path: royaloak@ezmini.com
Attachment Name: #UE00S802H.ISO
Attachment SHA256: d625b68606f5221ef6893109ebd3682ddef07dbdb120688fc1626305aeb1ff6a
UDF_Encapsulated_Executable Name: #UE00S802H.js
VjW0rm JavaScript Dropper SHA256: 8af76d1916ebc77d52162659733ff74656dfa8955fc0d60e92dc1fb9a86c29fa
DE