General

  • Target

    XC12lient.exe

  • Size

    60KB

  • MD5

    80000eb10a99df44b557670aded4d0bf

  • SHA1

    861f71e942652a8cea932de335c1d577e3147299

  • SHA256

    2297d34f5b6e39fb06ea7ee6f9fb1c6572b7a98b4c76a5c3bfd4dd351926b1ff

  • SHA512

    c88d3af7ed0b1005da734f40a9947f44eef68d769086f906855d4a718584ee84eed14c2b963aed433aaefba2b4bd57e03a1cc92b1f1712e6d40b4cac80c3f6da

  • SSDEEP

    1536:iNqQAXim/v4vO9Hru5o8eWwbH3EanV6EOcOSED:icZ/m8HreoJbHHHOcOTD

Score
10/10

Malware Config

Extracted

Family

xworm

Version

3.1

C2

2.tcp.eu.ngrok.io:11215

Attributes
  • Install_directory

    %AppData%

  • install_file

    USB.exe

Signatures

  • Detect Xworm Payload 1 IoCs
  • Xworm family
  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

Files

  • XC12lient.exe
    .exe windows:4 windows x86 arch:x86

    f34d5f2d4577ed6d9ceec516c1f5a744


    Headers

    Imports

    Sections