🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://13.92.159.78:6430.

Database Entry


IOC ID:249510
IOC: http://13.92.159.78:6430
IOC Type :url
Threat Type :botnet_cc
Malware: Vjw0rm
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS8075 MICROSOFT-CORP-MSN-AS-BLOCK
Country:- US
First seen:2021-11-15 21:59:14 UTC
Last seen:never
UUID:45b3b7bd-465f-11ec-8ab6-42010aa4000a
Reporter AndreGironda
Reward 5 credits from ThreatFox
Tags:Vjw0rm
Reference: https://tria.ge/211115-1bty7agebr

Avatar
AndreGironda
MITRE T1566.001
Date: Mon, 15 Nov 2021 08:00-08:30 -0800
Received: from smtp108.iad3a.emailsrvr.com (173.203.187.108)
From: "Dabbie"<sloopfor2@1791.com>
Subject: Payment Receipt.
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----=_NextPart_000_0123_01C2A9A6.40E7C562"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
X-Classification-ID: 1f3c6bb3-2e8d-48dd-a70f-ee5dfc22f8b6-1-1
Message-ID: <e91688d8-3572-4677-ab15-30d2888998ee@CO1NAM11FT064.eop-nam11.prod.protection.outlook.com>
To: Undisclosed recipients:;
Return-Path: sloopfor2@1791.com
Attachment Name: #BS0932MTANS622.zip
Attachment SHA256: e1084ccc222cfe21897e8ae5b83cdd7c7e0a174e0892674aea2276af93dc27ab
Unzipped Container Name: #BS0932MTANS622.iso
Container SHA256: 49de1486da8e0260248822d29129e3bf73ba3db8d94fb933571ab020934626f5
Contained JavaScript Dropper Name: #BS0932MTANS622.js
JS Dropper SHA256: ca65bd6a5fc3f9263908d87b4fd4dd70e1f1f83c67c3ea740132595a40dd6c52