General

  • Target

    https://github.com/koyaxZ/XWorm-v5-Remote-Access-Tool/releases/download/download/XWorm.rar

  • Sample

    240628-qzwskssejf

Score
10/10

Malware Config

Targets

    • Target

      https://github.com/koyaxZ/XWorm-v5-Remote-Access-Tool/releases/download/download/XWorm.rar

    Score
    10/10
    • Detect rhadamanthys stealer shellcode

    • Rhadamanthys

      Rhadamanthys is an info stealer written in C++ first seen in August 2022.

    • Executes dropped EXE

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

3
T1012

Peripheral Device Discovery

1
T1120

System Information Discovery

2
T1082

Tasks