🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 194.147.140.4:6161.

Database Entry


IOC ID:839821
IOC: 194.147.140.4:6161
IOC Type :ip:port
Threat Type :botnet_cc
Malware: Vjw0rm
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS208476 AS-ROOTLINK
Country:- IT
First seen:2022-07-27 14:44:07 UTC
Last seen:never
UUID:91549e40-0dba-11ed-b49e-42010aa4000a
Reporter AndreGironda
Reward 5 credits from ThreatFox
Tags:Vjw0rm
Reference: https://tria.ge/220727-rxwv8segbr

Avatar
AndreGironda
MITRE T1566.001
Date: Wed, 27 Jul 2022 12:00-12:30 +0100
Received: from mailout04.t-online.de (194.25.134.18)
Content-Type: multipart/mixed; boundary="===============2087037790=="
MIME-Version: 1.0
Subject: Avfuel Cards - Activity Remittance
To: Recipients <cfbilling1@avfuel.com>
From: "cfbilling" <sauck.mail@t-online.de>
Message-ID: <1oGevA-3mIUdS0@fwd81.t-online.de>
X-TOI-EXPURGATEID: 150726::1658920234-0144E3C8-A922DDAC/19/7578049373 SUSPECT MAIL-COUNT
X-TOI-MSGID: 9d5ca763-1124-4b19-b342-a70424d33225
Return-Path: sauck.mail@t-online.de
Attachment Name: 19756.html
HTML Smuggling SHA256: f9c5b5d6605d03147d803cae56ddb3adf04a519e0ddba6bb385e10602d335155
Password -- 2110
Stage URL: hXXps://cdn.discordapp[.]com/attachments/949311421773148254/1001722055538003978/19756.rar
Rarfile SHA256: 06e652fdfa96caf9801ed19bc4b8a054d83a646ae5c7fbfad66fa104d4789482
Uncompressed JavaScript Dropper Name: 19756.js
JS Dropper SHA256: a345c97da02b3c4b545a534a081fe143fb31df37462c74c36f9fa69329c68b65
VjW0rm JS Dropper SHA256: 03d170226c83a1a0504cca41a101658d34c7625481393f3b4681c3bda14cb889