General

  • Target

    Unconfirmed 155663.crdownload

  • Size

    5.0MB

  • MD5

    4009932a7e44d607b529598df00ff375

  • SHA1

    ff8bff1c6f707101215aee8d7ff315cba991001d

  • SHA256

    50505aa9a36faa076b8a6894297bc8fed02269938e6592b7b7be7c9c809897dd

  • SHA512

    b77816e1aaaf9a09155f91aa91070a099fcd09acec92c28ac6afa4bdf2abcec3d4e1eaa028efc4ff9b0999fc6b90ceaa71146d9023aaecc074a49945364c38de

  • SSDEEP

    98304:pKF5kw1zDBMXSm5yH6FhCUJ4LGH2TqYeRTZ6Im81Xvm/UxRrBMGxaz5naIizTKM:Ic0ev5yaSU6GH2Th2TZsEfms+/kzOM

Score
3/10

Malware Config

Signatures

  • Unsigned PE 6 IoCs

    Checks for missing Authenticode signature.

Files

  • Unconfirmed 155663.crdownload
    .zip
  • XWorm-v5-Remote-Access-Tool-main/ComponentFactory.Krypton.Toolkit.dll
    .dll windows:4 windows x86 arch:x86

    dae02f32a21e03ce65412f6e56942daa


    Headers

    Imports

    Sections

  • XWorm-v5-Remote-Access-Tool-main/ComponentFactory.Krypton.Toolkit.pdb
  • XWorm-v5-Remote-Access-Tool-main/D3DX9_43.dll
    .dll windows:6 windows x64 arch:x64

    336d8057d1db03e5a3ac3b62e8902f4b


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • XWorm-v5-Remote-Access-Tool-main/Krypton.Toolkit.dll
    .dll windows:4 windows x86 arch:x86

    dae02f32a21e03ce65412f6e56942daa


    Headers

    Imports

    Sections

  • XWorm-v5-Remote-Access-Tool-main/LICENSE
  • XWorm-v5-Remote-Access-Tool-main/Mono.Cecil.dll
    .dll windows:4 windows x86 arch:x86

    dae02f32a21e03ce65412f6e56942daa


    Headers

    Imports

    Sections

  • XWorm-v5-Remote-Access-Tool-main/Mono.Nat.dll
    .dll windows:4 windows x86 arch:x86

    dae02f32a21e03ce65412f6e56942daa


    Headers

    Imports

    Sections

  • XWorm-v5-Remote-Access-Tool-main/README.md
  • XWorm-v5-Remote-Access-Tool-main/VMProtectSDK64.lib
  • XWorm-v5-Remote-Access-Tool-main/Vestris.ResourceLib.dll
    .dll windows:4 windows x86 arch:x86

    dae02f32a21e03ce65412f6e56942daa


    Headers

    Imports

    Sections

  • XWorm-v5-Remote-Access-Tool-main/XWorm.config
    .xml
  • XWorm-v5-Remote-Access-Tool-main/XWorm.exe
    .exe windows:4 windows x86 arch:x86

    eca0c30b65294d02a6c6180a6b323b58


    Headers

    Imports

    Sections

  • XWorm-v5-Remote-Access-Tool-main/imgui.ini