General

  • Target

    Virus-ast7qar.exe

  • Size

    133KB

  • Sample

    240701-nzfegstaqp

  • MD5

    ad23e3a028bc78b343633398624cdddb

  • SHA1

    d1a45e6391417289b4bc1f7bf37e10f38538a271

  • SHA256

    c70c923e6611ed32f74bf3b0e2083f8defd483528e91ca8a667cdfc8eb0b2a30

  • SHA512

    2d21aa9fc0ba3b0f33e65d6a8ce2827a8703e1ace688b48040f2da5e92afd85ffa87e8cd97722d559d006b744e4c56ca083dead1a75f04ba2d2b243e396f0f71

  • SSDEEP

    3072:8WjMV1c/jsm1RIj9+bpsCBOgC4lOGmOl4CZUFkEC3Qy5Vj54Lzo:8QMV1Awm12Ib3OgvWOl4CZUFkECAy5VO

Score
10/10

Malware Config

Extracted

Family

xworm

C2

147.185.221.18:46309

Attributes
  • Install_directory

    %AppData%

  • install_file

    PsTeam.exe

Targets

    • Target

      Virus-ast7qar.exe

    • Size

      133KB

    • MD5

      ad23e3a028bc78b343633398624cdddb

    • SHA1

      d1a45e6391417289b4bc1f7bf37e10f38538a271

    • SHA256

      c70c923e6611ed32f74bf3b0e2083f8defd483528e91ca8a667cdfc8eb0b2a30

    • SHA512

      2d21aa9fc0ba3b0f33e65d6a8ce2827a8703e1ace688b48040f2da5e92afd85ffa87e8cd97722d559d006b744e4c56ca083dead1a75f04ba2d2b243e396f0f71

    • SSDEEP

      3072:8WjMV1c/jsm1RIj9+bpsCBOgC4lOGmOl4CZUFkEC3Qy5Vj54Lzo:8QMV1Awm12Ib3OgvWOl4CZUFkECAy5VO

    Score
    10/10
    • Detect Xworm Payload

    • Xworm

      Xworm is a remote access trojan written in C#.

    • Drops startup file

MITRE ATT&CK Matrix ATT&CK v13

Tasks