General

  • Target

    XCl1ient.exe

  • Size

    60KB

  • MD5

    a0808b7618eb5893c254173472d1adcd

  • SHA1

    9ec40f929de580cf65697b62ffa73c98e74d81a8

  • SHA256

    1daf0068b904a151117993bd6004d6097eaf104995e00e25785a26d78f8abf0a

  • SHA512

    982afbac94e7e83046b7f9aafc5fc4f9c578dc1bb2972e29211d78328b5a363892a78ca287bcb49b8a2b2fa96092b0ae3eb0b17891fc21f4cedf5abca3046602

  • SSDEEP

    768:Rwb4vnaiY9W8vk93noPqu/Ug1WPZ9Irbt6LBI2Ticie6WOWhUAAoenk:R5vai+Zxcg+ZKbgLC2TUe6WOWeJtk

Score
10/10

Malware Config

Extracted

Family

xworm

Version

3.1

C2

0.tcp.eu.ngrok.io:12233

Attributes
  • Install_directory

    %AppData%

  • install_file

    USB.exe

Signatures

  • Detect Xworm Payload 1 IoCs
  • Xworm family
  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

Files

  • XCl1ient.exe
    .exe windows:4 windows x86 arch:x86

    f34d5f2d4577ed6d9ceec516c1f5a744


    Headers

    Imports

    Sections