ThreatFox IOC Database
You are viewing the ThreatFox database entry for url http://dbmne20.duckdns.org:8832.
Database Entry
This IOC expired
This IOC is an old IOC and hence has expired on 2026-09-15 10:39:25 UTC. We therefore refrain from exporting it into our datasets. As a result, this database entry is purely informational and has no impact.
| IOC ID: | 245455 |
|---|---|
| IOC: | http://dbmne20.duckdns.org:8832 |
| IOC Type : | url |
| Threat Type : | botnet_cc |
| Malware: | Vjw0rm |
| Confidence Level : | Confidence level is high (100%) |
| Is compromised? : | False |
| ASN: | AS27323 SERVERSTADIUM |
| Country: | US |
| First seen: | 2021-11-08 17:19:30 UTC |
| Last seen: | never |
| UUID: | 08a7ddfd-40b8-11ec-8ab6-42010aa4000a |
| Reporter | |
| Reward | 5 credits from ThreatFox |
| Tags: | Vjw0rm |
| Reference: | https://tria.ge/211108-vfegeacgb3 |
AndreGironda
MITRE T1566.001Date: Mon, 8 Nov 2021 07:30-08:00 -0800
Received: from smtp66.ord1d.emailsrvr.com (184.106.54.66)
X-Auth-ID: brooksidecrossing@garibaldico.com
From: "Dabbie"<brooksidecrossing@garibaldico.com>
Subject: Invoice Order #HB00UN8330 Attached
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----=_NextPart_000_0037_01C2A9A6.3BA21DB6"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
X-Classification-ID: 61e9b287-363b-4b5d-b140-8261bbf572bf-1-1
Message-ID: <d0310c93-97fc-4fda-8f9f-d72dfe17c33a@CO1NAM11FT044.eop-nam11.prod.protection.outlook.com>
To: Undisclosed recipients:;
Return-Path: brooksidecrossing@garibaldico.com
Attachment Name: HB00UN_Copy.iso
Attachment SHA256: 81e404c97700d97eb4ed9274f84071f48ab947f297afac6367234995467c0c1b
Contained JavaScript Dropper Name: HB00UN_Copy.js
VjW0rm JS Dropper SHA256: 39a2889a8f27f0c875f04ac82ebefb26247e41f88c5b2824f649748901ae3a6a
US