General

  • Target

    Packages.exe

  • Size

    75KB

  • MD5

    e1b71f4ba193223fc5569d6c2c8987d8

  • SHA1

    ab0634c9bc987c434b55896cd9b1523af1280571

  • SHA256

    15af6ab42b15ed39a5257f1e750c728accb88dc332162937f1fd22ba314b7afa

  • SHA512

    d98ae8f4d37bdae664a4d703c5d5bc0a57f1cdc992fca0aad080863cd68b19b63e50c327de541bd9ca2a12582ecb23ff61344a3bca173574c563fa45a4d951a8

  • SSDEEP

    1536:b61UmSLuLfh3THEpbHhE+3lDZ6BwqTD+EViiODLkhpI:eumVfVTMbHhfA9ViiODLk/I

Score
10/10

Malware Config

Extracted

Family

xworm

C2

193.161.193.99:22901

Ironthing-22901.portmap.host:22901

Attributes
  • Install_directory

    %AppData%

  • install_file

    Packages.exe

Signatures

  • Detect Xworm Payload 1 IoCs
  • Xworm family
  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

Files

  • Packages.exe
    .exe windows:4 windows x86 arch:x86

    f34d5f2d4577ed6d9ceec516c1f5a744


    Headers

    Imports

    Sections