🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://dbmne20.duckdns.org:8832.

Database Entry


IOC ID:245455
IOC: http://dbmne20.duckdns.org:8832
IOC Type :url
Threat Type :botnet_cc
Malware: Vjw0rm
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS27323 SERVERSTADIUM
Country:- US
First seen:2021-11-08 17:19:30 UTC
Last seen:never
UUID:08a7ddfd-40b8-11ec-8ab6-42010aa4000a
Reporter AndreGironda
Reward 5 credits from ThreatFox
Tags:Vjw0rm
Reference: https://tria.ge/211108-vfegeacgb3

Avatar
AndreGironda
MITRE T1566.001
Date: Mon, 8 Nov 2021 07:30-08:00 -0800
Received: from smtp66.ord1d.emailsrvr.com (184.106.54.66)
X-Auth-ID: brooksidecrossing@garibaldico.com
From: "Dabbie"<brooksidecrossing@garibaldico.com>
Subject: Invoice Order #HB00UN8330 Attached
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----=_NextPart_000_0037_01C2A9A6.3BA21DB6"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
X-Classification-ID: 61e9b287-363b-4b5d-b140-8261bbf572bf-1-1
Message-ID: <d0310c93-97fc-4fda-8f9f-d72dfe17c33a@CO1NAM11FT044.eop-nam11.prod.protection.outlook.com>
To: Undisclosed recipients:;
Return-Path: brooksidecrossing@garibaldico.com
Attachment Name: HB00UN_Copy.iso
Attachment SHA256: 81e404c97700d97eb4ed9274f84071f48ab947f297afac6367234995467c0c1b
Contained JavaScript Dropper Name: HB00UN_Copy.js
VjW0rm JS Dropper SHA256: 39a2889a8f27f0c875f04ac82ebefb26247e41f88c5b2824f649748901ae3a6a