General

  • Target

    XClient.exe

  • Size

    70KB

  • MD5

    1aee9a35a708cb39e8cb4d77493ea266

  • SHA1

    734371aca4a8f81bc8da952687dfe3c9315fdbde

  • SHA256

    69062434a621587b25a7502d5384bed98f5002d34f5e5604abfb7b81d80cf29d

  • SHA512

    108f32dbede91c7552a88046d6cf92b49945744e0bbea380c2a880d460326c66e2ef28948fd2395e6976d6976fa83c974e2f70e9c05ba7b856dd82c2d713e6f2

  • SSDEEP

    1536:1uHWDFSwUrZS8Pm/ZZbZWfweYcYX67lwO+zfh9G:g2sVSS6ZbZBTAlwO+zfLG

Score
10/10

Malware Config

Extracted

Family

xworm

Version

3.1

C2

0.tcp.eu.ngrok.io:15792

Attributes
  • Install_directory

    %ProgramData%

  • install_file

    USB.exe

Signatures

  • Detect Xworm Payload 1 IoCs
  • Xworm family
  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

Files

  • XClient.exe
    .exe windows:4 windows x86 arch:x86

    f34d5f2d4577ed6d9ceec516c1f5a744


    Headers

    Imports

    Sections