General

  • Target

    Packages.exe

  • Size

    65KB

  • MD5

    9f2f801d5f2624439f4b757a67f3fab2

  • SHA1

    0d214685df8605df7ed843d92f8c8be1ba037a55

  • SHA256

    f5cad2530c21ab85cf6159d6c621ddcd45de189089b52658f345a8853df86291

  • SHA512

    7b2aa3f6d5d67d22df8844ce5317310b915c7059e152814a3b8b2fa3e28a027c2c0e349ebe3e043515e59d2df33f40a046b19a65364c82525b12b9bc281a640c

  • SSDEEP

    1536:yho9uTlvBPo4N6Zlbe5rqqMD6UfOLoVuW:yhkCxNo4Nabe5qfOEoW

Score
10/10

Malware Config

Extracted

Family

xworm

C2

Ironthing-22901.portmap.host:22901

field-clark.gl.at.ply.gg:22901

Attributes
  • Install_directory

    %AppData%

  • install_file

    Packages.exe

Signatures

  • Detect Xworm Payload 1 IoCs
  • Xworm family
  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

Files

  • Packages.exe
    .exe windows:4 windows x86 arch:x86

    f34d5f2d4577ed6d9ceec516c1f5a744


    Headers

    Imports

    Sections