🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://franmhort.duia.ro:8152/Vre.

Database Entry


IOC ID:696909
IOC: http://franmhort.duia.ro:8152/Vre
IOC Type :url
Threat Type :botnet_cc
Malware: Vjw0rm
Confidence Level : Confidence level is high (100%)
Is compromised? : False
First seen:2022-06-13 03:48:48 UTC
Last seen:never
UUID:bb89d521-eacb-11ec-a975-42010aa4000a
Reporter AndreGironda
Reward 5 credits from ThreatFox
Tags:Houdini Vjw0rm WSHRAT
Reference: https://tria.ge/220613-d169gsdeen

Avatar
AndreGironda
MITRE T1566.001
Date: Sun, 12 Jun 2022 22:00-22:30 -0500
Received: from mailsv01.psysnet.com (210.230.250.137)
Content-Type: multipart/mixed; boundary="===============0103115937=="
MIME-Version: 1.0
Subject: Re: Urgent Order pricelist
To: Recipients <Kim.j@cowellfashion.co.kr>
From: " Kim Ghazali / Sales" <Kim.j@cowellfashion.co.kr>
X-AV-Checked: anti-virus scanned: PSYSNET.COM
Message-ID: <8552b5bf-b45e-4cdc-8213-00889b27a7ec@CO1NAM11FT047.eop-nam11.prod.protection.outlook.com>
Return-Path: Kim.j@cowellfashion.co.kr
Attachment Name: NEW-PO.zip
Zipfile SHA256: 7dc271ee8fea7c64942a7b5acd13b5ccf139e6dd910883b029288b77f1a642a3
Unzipped JavaScript Dropper Name: NEW-PO.js
JS Dropper SHA256: 9446c38b335edc7d0dbfa754ad0a8f1a41de185f83722b43816b739c3ceb74f4
VjW0rm SHA256: 3fcc843e8735f172c8746f473f042cc7bf796cad0b25f4d2e210251e206f9b43
WSHRAT / Houdini RAT SHA256: 185182f369edcb96118a91dcad39eb5b63239112ed6963a8c274178bf1b55394

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2022-06-20 07:37:41 d6d4d55f2df43c5d2a35a96b53ac0f949673a901ce8aeb41ed1144ecb7b3ba09