ThreatFox IOC Database
You are viewing the ThreatFox database entry for ip:port 37.120.141.147:9032.
Database Entry
This IOC expired
This IOC is an old IOC and hence has expired on 2026-09-15 08:57:25 UTC. We therefore refrain from exporting it into our datasets. As a result, this database entry is purely informational and has no impact.
| IOC ID: | 352300 |
|---|---|
| IOC: | 37.120.141.147:9032 |
| IOC Type : | ip:port |
| Threat Type : | botnet_cc |
| Malware: | Vjw0rm |
| Confidence Level : | Confidence level is high (100%) |
| Is compromised? : | False |
| ASN: | AS9009 M247 |
| Country: | RO |
| First seen: | 2022-01-27 18:06:36 UTC |
| Last seen: | 2023-08-01 06:55:31 UTC |
| UUID: | de465182-7f9b-11ec-a824-42010aa4000a |
| Reporter | |
| Reward | 5 credits from ThreatFox |
| Tags: | Vjw0rm |
| Reference: | https://tria.ge/220127-v75gxagean |
AndreGironda
MITRE T1566.001Date: Thu, 27 Jan 2022 08:00-08:30 -0800
Received: from smtp118.ord1d.emailsrvr.com (184.106.54.118)
X-Auth-ID: invoiceme@janemeadows.com
From: "Candy"<invoiceme@janemeadows.com>
Subject: PAYMENT SENT
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----=_NextPart_000_00BB_01C2A9A6.4ECEF172"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
X-Classification-ID: 13d112bf-5cbe-46ea-a28b-bdede0381a91-1-1
Message-ID: <87307b27-02e1-4a0a-826e-6f4cd521a7c9@CO1NAM11FT024.eop-nam11.prod.protection.outlook.com>
To: Undisclosed recipients:;
Return-Path: invoiceme@janemeadows.com
Attachment 1 Name: RT001.zip
Attachment 1 SHA256: de1de1e6a42be92dd057249c295c3e3181b8b6ff66b788b1ae7ab5d8ae4b5896
Attachment 2 (this C2 connect) Name: RT002.zip
Attachment 2 SHA256: ebb17799ce4f0fd8b64db8b3651006675f5f9be424e877e89c5cedde8f42b7d2
Unzipped Container 1 Name: YBXVDXZSJEEZLNOISHXB.iso
Unzipped Container 1 SHA256: dfdf9e2c8229090b957b08957f4cdb20a687ae7466d56e5f602c8309b36aaf1a
Unzipped Container 2 Name: YSOKNUOW.iso
Unzipped Container 2 SHA256: 6aab37367b684ccf1a5a1593c4bb529b4464594db1d06a4affe919841a4467da
Contained VBScript Name: YBXVDXZSJEEZLNOISHXB.vbs
Contained VBScript SHA256: d230708d5f6e554f91ed4b51521fc6f77aa151d289859b9bfd7aa78adcd1084b
Contained JavaScript Dropper Name: YSOKNUOW.js
VjW0rm JS Dropper SHA256: 9b1f2d3e06f9a6299287c531f007e1f2a38fd1d5af3481e7f6be24475495567d
RO