General

  • Target

    x433.exe

  • Size

    762KB

  • Sample

    240630-qpnzzssajp

  • MD5

    148ec472df90b0fb274c3ce2ad2e811f

  • SHA1

    378ba02b08494b36ff5a2674cf99eba6c7025d6a

  • SHA256

    a08b846be9052a2614ef6a6920260d465774f5da9926f6d08449a2e4eb27b787

  • SHA512

    ab6764b598d538bc726a1e0baf02c8c4a2ccdedf77ff6b3ee63d1e27c0a05e13423142b86f38afbd9462c0d90b5c3a9963a30e110145aca455ffa5403375c5b1

  • SSDEEP

    12288:0sjApTtnb0TbQxMM90CL7VmADH2eJGCOTJfVXwAfIXZqPtbxZWdezgrrNo02UBYW:djuTt4TbQRjDH2eJQTNqcWOVZK1y02UH

Score
10/10

Malware Config

Extracted

Family

xworm

C2

session-chief.gl.at.ply.gg:36125

Attributes
  • Install_directory

    %LocalAppData%

  • install_file

    x4usb.exe

Targets

    • Target

      x433.exe

    • Size

      762KB

    • MD5

      148ec472df90b0fb274c3ce2ad2e811f

    • SHA1

      378ba02b08494b36ff5a2674cf99eba6c7025d6a

    • SHA256

      a08b846be9052a2614ef6a6920260d465774f5da9926f6d08449a2e4eb27b787

    • SHA512

      ab6764b598d538bc726a1e0baf02c8c4a2ccdedf77ff6b3ee63d1e27c0a05e13423142b86f38afbd9462c0d90b5c3a9963a30e110145aca455ffa5403375c5b1

    • SSDEEP

      12288:0sjApTtnb0TbQxMM90CL7VmADH2eJGCOTJfVXwAfIXZqPtbxZWdezgrrNo02UBYW:djuTt4TbQRjDH2eJQTNqcWOVZK1y02UH

    Score
    10/10
    • Detect Xworm Payload

    • Xworm

      Xworm is a remote access trojan written in C#.

MITRE ATT&CK Matrix

Tasks