General

  • Target

    7574843f91261ab512b368ce7942d6ae.bin

  • Size

    19KB

  • MD5

    db26888f69e322e211dde950651e6866

  • SHA1

    76f1a070cfacf6c47ff8251e67f83dd904082d7e

  • SHA256

    804a92bb8ebfbe27bc482e76e2d8675f33f4257d3497a92105dc8bfa09011153

  • SHA512

    a4f9e6994db5f332fb9eafbe484396a9a98ad6d43223841bb7daa03705f65c1c5b4ef876688d550a0d61451467752f64539092c5efa10007be416aa95a6c60e5

  • SSDEEP

    384:2svaJOD5T6mNqwhT/fAYcuvwswWbM4r3CcosdouIq+d2QJuuV920IBg:gebh0XWg4T/hS56Tg

Score
10/10

Malware Config

Extracted

Family

xworm

Version

5.0

C2

64.23.249.117:6098

Mutex

qBm7HSWbfhJrOf6O

Attributes
  • Install_directory

    %AppData%

  • install_file

    XClient.exe

aes.plain

Signatures

  • Detect Xworm Payload 1 IoCs
  • Xworm family
  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

Files

  • 7574843f91261ab512b368ce7942d6ae.bin
    .zip

    Password: infected

  • c826d38990051067a23d7ced76e20925ec47749e562ef718029ff06555680b5b.exe
    .exe windows:4 windows x86 arch:x86

    Password: infected

    f34d5f2d4577ed6d9ceec516c1f5a744


    Headers

    Imports

    Sections