🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 07c22483416fb7e222da7e1d990b1cbfe3fa3cd3b855de01f206a661503f0dd6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



XWorm


Vendor detections: 10


Intelligence 10 IOCs YARA 2 File information Comments

SHA256 hash: 07c22483416fb7e222da7e1d990b1cbfe3fa3cd3b855de01f206a661503f0dd6
SHA3-384 hash: b42a2e0b9cab2f180aa0fb7ffa6fbe778524170af1060e6c909a1f71614b0a51fff00ef6caaedda2f75a72bd63f5082a
SHA1 hash: b0f6392e83d535659f8ddbe2780f347587b73e72
MD5 hash: 7e103fb8a1a7993aaf59c5161a27461e
humanhash: bluebird-oxygen-shade-may
File name:PurchaseXOrder.zip
Download: download sample
Signature XWorm
File size:59'574 bytes
First seen:2026-05-20 17:18:51 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 1536:XwxIR6tiCeoP6sWgwpzV/Cn0IOrUlj+MKR52MmgN:XwCRKimP6sWjTqnu/RREIN
TLSH T1AD4302C801FCE569DB8EC92955FA2E44A02D01D46718E711AD2A5BE344E6B470ECFBAC
Magika zip
Reporter TomU
Tags:xworm zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
45
Origin country :
CH CH
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:output_1760945404.vbs
File size:274'852 bytes
SHA256 hash: e0d40091b7f7904d8801fd6d1a67164e02d148035824948bc4a5e255e6fb4876
MD5 hash: ad388c99e911fc79ad56b64578089264
MIME type:text/plain
Signature XWorm
Vendor Threat Intelligence
Verdict:
Malicious
Score:
96.5%
Tags:
virus spawn blic
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
aes anti-vm base64 base64 cmd crypto evasive fingerprint lolbin obfuscated packed powershell powershell reconnaissance
Verdict:
Malicious
File Type:
zip
First seen:
2025-10-20T08:25:00Z UTC
Last seen:
2025-11-17T18:21:00Z UTC
Hits:
~10
Gathering data
Threat name:
Script-WScript.Trojan.XWorm
Status:
Malicious
First seen:
2025-10-20 11:14:54 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
20 of 38 (52.63%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ClamAV_Emotet_String_Aggregate

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

XWorm

zip 07c22483416fb7e222da7e1d990b1cbfe3fa3cd3b855de01f206a661503f0dd6

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments