Currently analysing a sample of the vjw0rm js malware but I don't know how to find the hidden ioc

Viewed 63

So for the last couple of days I have been practicing some basic malware analysis on mainly macro malware like Agent Tesla but this time I am trying to figure out how solve the logic of the vjworm javascript malware and so far I have managed to deobfuscate the code using a combination of both manual deobfuscation and an online tool.

This is the sample in it's deobfuscated form https://pastebin.com/qRBKix6V

I am not able to post the entire thing here on Stackoverflow so I posted it on pastebin because it's just too large for the post limit of 30000 characters so I will post a snippet of the code instead and it's a piece of the code I am struggling to wrap my head around where it looks to be base64 and I did try convert it into text using a base64 to text online tool and I was promptly told that this was actually code and that I should convert to the bin format and I could read the output before I downloaded it and it was just a bunch of random letters with no meaning at all What does this mean?.

function t() {
  var Nd = ["W68xWPnGW59PWQiEnaC", "yMeBqSoNWPxdO8kT", "omkdW6ddQq", "q2XVC2u", "W7/dPCkWWPpdNfldVG", "WOHnWONcTtXLWPH+WQPb", "sSkzfq", "A3LWzsaVDhiGiG", "vbVdSSk7WOK", "Evz3tuK", "fSoHxmk9C1ldPq", "WOtcLSozW6S", "W7ebWPBcRaCxW5BcJrn0", "Ahr0CdOVl2DYyq", "atP8ssW", "gL3cMG", "C3bSAxq", "u2XLzxa", "B3bLBG", "tfNdJGddR8oFqSkHW7u", "W4RdPCo4aN/cIw9Ifmk4WPv1", "Dg9tDhjPBMC", "BsS0ga", "rhhcT3lcKXpcT8keW4tdMG", "jvjNtMuL", "WRpcTCoyW6/cQq", "mhWZFdr8mxWY", "ue9tva", "W5SibaddMmkMumo4", "mZmWt3Lsrvfe", "FY3dPHZcOcdcJ8kSWQJdQa", "lrJcQ8oRWQFdGSoaWPW6W4y", "aCo/fvxdJMuaD8oyW6C", "W5nKW68+ntGvEConeZ0", "W4pcJSkO", "Dub7or8", "hGnwAbvOcSo6W79/", "BgVcGwJcLG", "uMvNv3jPDgu", "xhjVB3rCC2vJDq", "W6LEA19k", "W4TgW6VdR3i", "WOTqgrldVmkDEmo4", "W7FcVSk1CmoBpW", "BuDAtKS", "WPNcNhqRWQ0", "t8kAztlcQmkrhW", "W5tdLahdNCoEW7KYmSkacW", "fSo0W4xcMN0XW5TDi2S", "tCoEWRJcVutcP2SJn8oMWQi", "twLJCM9ZB2z0xa", "WO9uwKZcHmk0CSoniSkIW5W", "WRZdJGtdI8od", "ef/dM8kau8olW6jFn8k6", "yxbWBhK", "jxZcVSkgWPe", "F8oPvW", "mJy0vhv2vgXi", "WRtdVMm1", "qCk4m8kNAM3dSHRdIq", "F2RcQG", "pCo5W6e7oaysu8oX", "hCodowFdS8osqSo5y8kogKFdVq", "WRyAkmk0kHuHFwS", "nxW0FdH8mW", "shHSz1O", "sXpdUmkUWO3dNCo7k8oWza", "WRiwj8kRlHa", "yMvRBKC", "AxrLBq", "WRJdH8ouWQRdKa", "u2HLBgWUqxbWBa", "W6PdW50", "W53dOCk0WPC", "oCk5xwJcSq", "atapCSoCWQxdMSk6", "zLDLuhG", "juVdHCoXW67cJxZdVSkLW4y", "ntG1odD2qKrRzNG", "ntuWmtK1DxjtC2nx", "we1msfruua", "ruPUEhu", "BG9MW58qWPJcPfddK8kt", "W7KibqBdKa", "jGVcQSk0W5JdLmkUi8kR", "W6nfA11+", "uxvPDa", "d8kDEvxcKa", "renDcdS", "W5/dVc7dVmo0", "WR5keSkhW7jdyCkca8o0sq0d", "WOVcVCkaDGS", "jedcRmo+W5NcNSoXoCoVCmkVWP8", "Bw92zu5LEhq", "wefJW5mcWP/cQeZdGSoy", "Ffz8", "EujSyvi", "yxrPBMDtExn0zq", "zgVcOwS", "h2hcOCkxWRRdOmkwqW", "DuPcfZ/cP3y", "rJ0XdLO", "CSonCJy+", "jJitWOhdHcldS8opbmkp", "rMLSzq", "ChnHBg1Zltu1", "betdKmkftSoC", "W6ZdTmkfWPhdMq", "uhjVz3jHBurHDa", "mNWWFdf8n3W2Fa", "FwPxW4BcMW", "v2LUzg93C1XdDq", "WPqHWRe", "xe1Py3jVC29MDa", "vxL4Cu0", "rgLZCgXHEu5HBq", "wuvt", "WQtcH8kLWPbpydzfWPRcVa", "W7vcW6BdQ3a", "u2nODgfZA3mGlW", "sw5ZDgfUy2vZtW", "odCZsgXrs2Do", "qSk+mvdcUa", "yxrfBMq", "vwDoC1u", "W7HfW5KHW6KFW6u", "zwXS", "z8kNcNTsWR3dKSoJWRFcVG", "u0XbD2O", "CMvWBgfJzq", "W6LiW4VcRXvNW47cJfro", "W4rrW7C", "yuXutgq", "v1nJCMLWDc5tAa", "W6ddVW7dJSoJ", "r1DNs2K", "wgDZtwq", "t3bLBLrLEhrgAq", "t3rYweK", "W5tdRSkoWRJdNa", "xfnVzNr3yxjLxa", "tqpcPt3cRZjFWP3dHH0", "zmkafgVcRSk1W6vYrmkn", "fmoGDSkksfNdGqK", "WONcU8k4WPbU", "qLFdR8k9uG", "qmoqwX8CW7bgzq", "Emo4W4hcKvS1W58EAq", "seTmtvXtt0zuvW", "uKvhx1nA", "CML0EwnLBNrLCG", "DCkclIO", "DgvTCa", "lK5fvfXgCMfTzq", "nKD6B3fbra", "BgXUvLa", "g2/dQSor", "mZq0mtjzv0rHwuG", "oCkNvf7cSsn5tu5t", "y29Kzeu", "udDfs09xqJzhsa", "rmo2W6xcTKK", "v3jPDgu"];

This is the malware sample in it's obfuscated form https://pastebin.com/xukFtPT7

My main goal here is to get an understanding about how the code functions and how it eventually get's to the ioc like ip adresses and domain names.

So far I have done some research around this malware but I found very little regarding how to reverse engineer this malware and the only resource I found did not have the same code as me.

I am by no means an expert at reverse engineering malware and I am not a master programmer by any means but I am able to read,write basic programs. But on the other hand I have watched many tutorials and read many resources regarding malware from different families and how to best analyse them using a combination of both tools and manual malware analysis both static and dynamic.

What should I do now?

0 Answers
Related