🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://moneymoment.duckdns.org:8834.

Database Entry


IOC ID:247193
IOC: http://moneymoment.duckdns.org:8834
IOC Type :url
Threat Type :botnet_cc
Malware: Vjw0rm
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS30823 AUROLOGIC
Country:- DE
First seen:2021-11-11 16:12:26 UTC
Last seen:never
UUID:29520a6b-430a-11ec-8ab6-42010aa4000a
Reporter AndreGironda
Reward 5 credits from ThreatFox
Tags:Vjw0rm
Reference: https://tria.ge/211111-tlavqsbeg7/behavioral1

Avatar
AndreGironda
MITRE T1566.001
Date: Thu, 11 Nov 2021 07:00-07:30 -0800
Received: from smtp86.iad3a.emailsrvr.com (173.203.187.86)
X-Auth-ID: martin.fernandez@toyotaofpoway.com
From: "Dabbie"<martin.fernandez@toyotaofpoway.com>
Subject: Invoice Order #TV003UGA Attached
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----=_NextPart_000_00C5_01C2A9A6.20AD032E"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
X-Classification-ID: 19c41344-f81d-4060-a5a6-679e2f72c38a-1-1
Message-ID: <9738923d-7d13-4480-bea6-7b5f020cf0a9@BN8NAM11FT054.eop-nam11.prod.protection.outlook.com>
To: Undisclosed recipients:;
Return-Path: martin.fernandez@toyotaofpoway.com
Attachment Name: TV003_Invoice#02189.iso
Attachment SHA256: 5fad065322759fdc6eb4e74afcdc5d3c02d910be9bcbc7c91b475fdc3b21cc4f
Contained JavaScript Dropper Name: TV003_Invoice#02189.js
Vjw0rm JS Dropper SHA256: 2b2d82a9d85104bce3d431a7fcbacd4652b25ae367cfd41b13e582b375d53183