🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 21023204fe1bc4709eebad56e04ed0ee0d4b6fd64b3cb89e8462109cdbde75d9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



XWorm


Vendor detections: 18


Intelligence 18 IOCs 1 YARA 10 File information Comments

SHA256 hash: 21023204fe1bc4709eebad56e04ed0ee0d4b6fd64b3cb89e8462109cdbde75d9
SHA3-384 hash: 16eb467807343dbc75574607fd14b3fc94384cf517b1f9d4e135e26a9546315285a6af5844043d20028816d5319e46e6
SHA1 hash: 1a19f029a9019f8dfd448cd4ee7833de8eb7d1ea
MD5 hash: 13b52743608a37569d1a42380a7d7c00
humanhash: fillet-california-pennsylvania-seventeen
File name:13b52743608a37569d1a42380a7d7c00.exe
Download: download sample
Signature XWorm
File size:2'886'335 bytes
First seen:2025-10-06 19:20:13 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 112bfbb18727302cb5425c20a464b02e (52 x XWorm, 2 x AsyncRAT)
ssdeep 49152:N0o9iQvv9WGLBy+lIvbu32MyToutyoQ1cd:NniQHkmy1y3JyZb
TLSH T179D58E1267EC40BAE1B392758DB98652E6F67C624B318FCF52944E0E2F339D15E34722
TrID 56.8% (.EXE) InstallShield setup (43053/19/16)
13.8% (.EXE) Win64 Executable (generic) (10522/11/4)
8.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
5.9% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon 346c246eaab296e2 (1 x XWorm)
Reporter abuse_ch
Tags:exe xworm


Avatar
abuse_ch
XWorm C2:
147.185.221.211:42500

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
147.185.221.211:42500 https://threatfox.abuse.ch/ioc/1608257/

Intelligence


File Origin
# of uploads :
1
# of downloads :
111
Origin country :
NL NL
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
13b52743608a37569d1a42380a7d7c00.exe
Verdict:
Malicious activity
Analysis date:
2025-10-06 19:50:59 UTC
Tags:
xworm auto rat auto-startup pastebin

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.9%
Tags:
asyncrat autorun
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file
Creating a process from a recently created file
Enabling the 'hidden' option for recently created files
Moving a recently created file
Сreating synchronization primitives
Creating a window
Creating a file in the %temp% subdirectories
Modifying an executable file
Creating a file in the Program Files subdirectories
DNS request
Connection attempt
Sending a custom TCP request
Connection attempt to an infection source
Delayed writing of the file
Unauthorized injection to a recently created process
Enabling autorun with the shell\open\command registry branches
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Query of malicious DNS domain
Infecting executable files
Enabling autorun by creating a file
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug anti-vm explorer fingerprint hacktool lolbin microsoft_visual_cc obfuscated overlay packed packer_detected regedit remote threat
Verdict:
Malicious
File Type:
exe x64
First seen:
2025-10-03T06:22:00Z UTC
Last seen:
2025-10-05T20:05:00Z UTC
Hits:
~100
Result
Threat name:
Detection:
malicious
Classification:
spre.troj.evad
Score:
76 / 100
Signature
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
Antivirus detection for dropped file
C2 URLs / IPs found in malware configuration
Connects to a pastebin service (likely for C&C)
Creates an undocumented autostart registry key
Drops executable to a common third party application directory
Drops or copies MsMpEng.exe (Windows Defender, likely to bypass HIPS)
Drops PE files to the document folder of the user
Found malware configuration
Infects executable files (exe, dll, sys, html)
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
May modify the system service descriptor table (often done to hook functions)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sample is not signed and drops a device driver
Sample uses string decryption to hide its real strings
Sigma detected: Files With System Process Name In Unsuspected Locations
Sigma detected: System File Execution Location Anomaly
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Yara detected XWorm
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1790153 Sample: BwI7ba3xq3.exe Startdate: 06/10/2025 Architecture: WINDOWS Score: 76 72 pastebin.com 2->72 74 also-body.gl.at.ply.gg 2->74 92 Found malware configuration 2->92 94 Malicious sample detected (through community Yara rule) 2->94 96 Antivirus detection for dropped file 2->96 100 12 other signatures 2->100 9 BwI7ba3xq3.exe 5 2->9         started        13 rundll32.exe 2->13         started        15 OpenWith.exe 2->15         started        signatures3 98 Connects to a pastebin service (likely for C&C) 72->98 process4 file5 56 C:\Users\user\Documents\shost.exe, PE32+ 9->56 dropped 58 C:\Users\user\Documents\audiodg.exe, PE32 9->58 dropped 60 C:\Users\user\Documents\RCXCB98.tmp, PE32+ 9->60 dropped 62 C:\Users\user\Desktop\BwI7ba3xq3..exe, PE32 9->62 dropped 106 Drops PE files to the document folder of the user 9->106 108 Creates an undocumented autostart registry key 9->108 110 May modify the system service descriptor table (often done to hook functions) 9->110 112 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 9->112 17 BwI7ba3xq3..exe 9->17         started        21 shost.exe 1360 9->21         started        23 audiodg.exe 15 5 9->23         started        signatures6 process7 dnsIp8 42 C:\Users\user\AppData\...\BwI7ba3xq3.64.exe, PE32+ 17->42 dropped 80 May modify the system service descriptor table (often done to hook functions) 17->80 82 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 17->82 26 shost.exe 17->26         started        44 C:\Users\user\Documents\RCXF1AA.tmp, PE32 21->44 dropped 46 C:\Users\user\...\948132792934-theThing.exe, PE32+ 21->46 dropped 48 C:\Users\user\AppData\...\934886053681.exe, PE32 21->48 dropped 52 146 other malicious files 21->52 dropped 84 Drops PE files to the document folder of the user 21->84 86 Drops or copies MsMpEng.exe (Windows Defender, likely to bypass HIPS) 21->86 88 Drops executable to a common third party application directory 21->88 90 Infects executable files (exe, dll, sys, html) 21->90 30 audiodg.exe 21->30         started        76 also-body.gl.at.ply.gg 147.185.221.211, 42500 SALSGIVERUS United States 23->76 78 pastebin.com 172.66.171.73, 443, 49718 CLOUDFLARENETUS United States 23->78 50 C:\Users\user\AppData\Local\winlogon, PE32 23->50 dropped 32 WerFault.exe 23->32         started        file9 signatures10 process11 file12 64 C:\Users\user\Documents\RCXF1DE.tmp, PE32 26->64 dropped 66 C:\Users\user\AppData\Local\...\RCXAB74.tmp, PE32+ 26->66 dropped 68 C:\Users\user\AppData\Local\...\RCXAB33.tmp, PE32+ 26->68 dropped 70 183 other malicious files 26->70 dropped 114 Drops executable to a common third party application directory 26->114 116 Infects executable files (exe, dll, sys, html) 26->116 34 BwI7ba3xq3.64.exe 26->34         started        38 BwI7ba3xq3.64.exe 26->38         started        40 audiodg.exe 26->40         started        signatures13 process14 file15 54 C:\Windows\System32\drivers\PROCMON23.SYS, PE32+ 34->54 dropped 102 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 34->102 104 Sample is not signed and drops a device driver 34->104 signatures16
Gathering data
Threat name:
Win64.Backdoor.XWorm
Status:
Malicious
First seen:
2025-09-30 07:49:00 UTC
File Type:
PE+ (Exe)
Extracted files:
110
AV detection:
26 of 36 (72.22%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
Similar samples:
Result
Malware family:
Score:
  10/10
Tags:
family:xworm discovery persistence rat trojan
Behaviour
Modifies registry class
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Adds Run key to start application
Legitimate hosting services abused for malware hosting/C2
Drops startup file
Executes dropped EXE
Modifies system executable filetype association
Detect Xworm Payload
Xworm
Xworm family
Unpacked files
SH256 hash:
21023204fe1bc4709eebad56e04ed0ee0d4b6fd64b3cb89e8462109cdbde75d9
MD5 hash:
13b52743608a37569d1a42380a7d7c00
SHA1 hash:
1a19f029a9019f8dfd448cd4ee7833de8eb7d1ea
SH256 hash:
cf96fbf20154e391280ec82a9818765345a061a4f9924a1e680cc3e20a212fc7
MD5 hash:
46924062b84a4d4c72c8dbeef73cb028
SHA1 hash:
2298358465b28528f39a42664314a08fa1fa9cdb
SH256 hash:
77f282dbc6d372e3bf8c6c74afeb9df7e742599031c16e2a8d0ff45782828b06
MD5 hash:
97bde3e526667ba5c9861f6b9be4f202
SHA1 hash:
2a13eebc49016386354b72c0d21771f6a56cfd51
SH256 hash:
120eb8f973110edbf98d989380461d9d12e874ec8f370d6d1929b6f5656b5613
MD5 hash:
d4f63efff50099d66b3a2806661afc96
SHA1 hash:
aefac013ea12d89880775921ee5775f17f339a90
SH256 hash:
edd730543b0f937b157a90ebd0d32b5efe0b287e37d186f38f044dca57f4e324
MD5 hash:
db6a5b5cc0f337f3323c88a115a38fac
SHA1 hash:
c1266cac36f58278127688bb8f00e1c7e59678f9
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_AllMal_Detector
Author:DiegoAnalytics
Description:CrossPlatform All Malwares Detector: Detect PE, ELF, Mach-O, scripts, archives; overlay, obfuscation, encryption, spoofing, hiding, high entropy, network communication
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerHiding__Thread
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:meth_stackstrings
Author:Willi Ballenthin
Rule name:skip20_sqllang_hook
Author:Mathieu Tartare <mathieu.tartare@eset.com>
Description:YARA rule to detect if a sqllang.dll version is targeted by skip-2.0. Each byte pattern corresponds to a function hooked by skip-2.0. If $1_0 or $1_1 match, it is probably targeted as it corresponds to the hook responsible for bypassing the authentication.
Reference:https://www.welivesecurity.com/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments