← Back to SOC feed Coverage →

ThreatFox: Vjw0rm IOCs

ioc-hunt HIGH ThreatFox
DnsEvents
iocthreatfoxwin-vjw0rm
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at ThreatFox →
Retrieved: 2026-07-18T23:00:00Z · Confidence: high

Hunt Hypothesis

This hunt hypothesis targets adversary behavior where malicious actors leverage specific ThreatFox indicators of compromise to establish persistence and execute command-and-control communications within the Azure environment. The SOC team should proactively hunt for these Vjw0rm IOCs in Azure Sentinel to identify early-stage infections before they escalate into broader lateral movement or data exfiltration incidents.

IOC Summary

Malware Family: Vjw0rm Total IOCs: 14 IOC Types: domain

TypeValueThreat TypeFirst SeenConfidence
domainfiscalnotificacionmunicipal.storepayload_delivery2026-07-18100%
domainfundacionolipica.storepayload_delivery2026-07-18100%
domainnotificadorlocalsolionesfis.storepayload_delivery2026-07-18100%
domainwww.remicionesexternas.storepayload_delivery2026-07-18100%
domainwww.firmaprincipal.storepayload_delivery2026-07-18100%
domaincomidarapidas.storepayload_delivery2026-07-18100%
domainsolicitudelarchivo.storepayload_delivery2026-07-18100%
domaincalzadoswer.storepayload_delivery2026-07-18100%
domaincominiucadosinternos.storepayload_delivery2026-07-18100%
domainnotificacionesnacionales.storepayload_delivery2026-07-18100%
domaincpantalonesnegro.storepayload_delivery2026-07-18100%
domainetiendasb.storepayload_delivery2026-07-18100%
domainbpadellcali.storepayload_delivery2026-07-18100%
domaindetalleselparaiso.storepayload_delivery2026-07-18100%

KQL: Domain Hunt

// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - Vjw0rm
let malicious_domains = dynamic(["fiscalnotificacionmunicipal.store", "fundacionolipica.store", "notificadorlocalsolionesfis.store", "www.remicionesexternas.store", "www.firmaprincipal.store", "comidarapidas.store", "solicitudelarchivo.store", "calzadoswer.store", "cominiucadosinternos.store", "notificacionesnacionales.store", "cpantalonesnegro.store", "etiendasb.store", "bpadellcali.store", "detalleselparaiso.store"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc

Required Data Sources

Sentinel TableNotes
DnsEventsEnsure this data connector is enabled

References

False Positive Guidance

Here are specific false positive scenarios for the ThreatFox: Vjw0rm IOCs detection rule in an enterprise environment, along with recommended filters or exclusions:

Original source: https://threatfox.abuse.ch/browse/malware/win.vjw0rm/