MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 364d3883e81da01bb449083552e5f1526ec734bdf40b27e71a4670fc3df12e76. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



XoriumStealer


Vendor detections: 17


Intelligence 17 IOCs YARA 3 File information Comments

SHA256 hash: 364d3883e81da01bb449083552e5f1526ec734bdf40b27e71a4670fc3df12e76
SHA3-384 hash: 27bf070c66b15fdfd458b1d5ccac432495ece1040a62a39727078ee5bbdad7a025b5f9cc1b93a3158d280130ca57ab2d
SHA1 hash: e2a6ffb0fe3813eeda24cef74fe77f9c24714a40
MD5 hash: 65c3aa0a48027921f2f94df9fd45c422
humanhash: missouri-steak-carbon-fillet
File name:winws.exe
Download: download sample
Signature XoriumStealer
File size:1'081'344 bytes
First seen:2026-07-25 15:05:21 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'125 x AgentTesla, 20'138 x Formbook, 12'362 x SnakeKeylogger)
ssdeep 12288:mceifO1cHqQA9UNEOIZBk1HIlnmMKr/kNiPDGd4GfjipfvzgiyBByiJv8TiMVlcL:ZCcKXZBZBk1HIlnm/a2G4y3v8GpQd
TLSH T19035019F251F8C52C4BD58B807BBB3C68B5C9D7A1661DC222C507E0A767C502B62BF2D
TrID 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.6% (.EXE) Win64 Executable (generic) (6522/11/2)
4.5% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
dhash icon d4c4b2b2aa8eb2a2 (1 x XoriumStealer)
Reporter Alex_sev
Tags:Dinberx dropper exe RAT XoriumStealer xworm

Intelligence


File Origin
# of uploads :
1
# of downloads :
182
Origin country :
AU AU
Vendor Threat Intelligence
Malware configuration found for:
EvilCoder SheetRat
Details
Malware family:
n/a
ID:
1
File name:
winws.exe
Verdict:
Malicious activity
Analysis date:
2026-07-25 15:31:12 UTC
Tags:
unixstealer stealer telegram evasion ip-check sheetrat rat

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Deleting a recently created file
Launching the process to change network settings
Searching for synchronization primitives
Creating a file in the Windows subdirectories
Launching cmd.exe command interpreter
Running batch commands
Enabling the 'hidden' option for recently created files
Adding an access-denied ACE
Sending a custom TCP request
Creating a file in the Windows directory
Enabling the libraries to load when starting the app (AppInit_DLLs)
Loading a suspicious library
Launching a process
Launching the process to change the firewall settings
Сreating synchronization primitives
Creating a file in the %temp% directory
Creating a process from a recently created file
Creating a file
DNS request
Connection attempt
Using the Windows Management Instrumentation requests
Sending an HTTP GET request
Reading critical registry keys
Unauthorized injection to a recently created process
Stealing user critical data
Blocking the User Account Control
Blocking the Windows Defender launch
Enabling autorun
Unauthorized injection to a system process
Enabling autorun by creating a file
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug anti-security anti-vm anti-vm base64 cdb cmd dllhost dropper evasive expand explorer fingerprint fingerprint hacktool lolbin msbuild netsh obfuscated packed privilege reconnaissance reconnaissance rootkit sc schtasks update vbnet
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-07-25T13:09:00Z UTC
Last seen:
2026-07-25T17:41:00Z UTC
Hits:
~100
Verdict:
inconclusive
YARA:
10 match(es)
Tags:
.Net Executable Managed .NET PE (Portable Executable) PE File Layout SOS: 0.21 Win 32 Exe x86
Threat name:
ByteCode-MSIL.Trojan.XWormRAT
Status:
Malicious
First seen:
2026-07-25 15:05:56 UTC
File Type:
PE (.Net Exe)
Extracted files:
23
AV detection:
27 of 36 (75.00%)
Threat level:
  5/5
Result
Malware family:
xorium_stealer
Score:
  10/10
Tags:
family:sheetrat family:xorium_stealer collection defense_evasion discovery evasion execution exploit persistence privilege_escalation ransomware spyware stealer trojan
Behaviour
Checks processor information in registry
Modifies data under HKEY_USERS
Modifies registry class
Runs net.exe
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
System policy modification
Uses Task Scheduler COM API
outlook_office_path
outlook_win_path
Browser Information Discovery
Enumerates physical storage devices
Event Triggered Execution: Netsh Helper DLL
Executes a command shell one-liner
System Network Configuration Discovery: Wi-Fi Discovery
Drops file in Windows directory
Launches sc.exe
Drops file in System32 directory
Accesses Microsoft Outlook profiles
Checks installed software on the system
Checks whether UAC is enabled
Enumerates connected drives
File and Directory Permissions Modification: Windows File and Directory Permissions Modification
Looks up external IP address via web service
Checks computer location settings
Creates new service(s)
Executes dropped EXE
Loads dropped DLL
Modifies file permissions
Reads WinSCP keys stored on the system
Reads user/profile data of web browsers
Registers new Windows logon scripts automatically executed at logon.
Stops running service(s)
Windows security modification
Command and Scripting Interpreter: PowerShell
Drops file in Drivers directory
Event Triggered Execution: AppInit DLLs
Modifies Windows Firewall
Possible privilege escalation attempt
Modifies boot configuration data using bcdedit
Detects Sheetrat Payload
Detects Sheetrat obfuscated V1.8 and higher
Detects Sheetrat obfuscated version
Detects XoriumStealer payload
Family: Sheetrat, NonEuclid rat
Family: XoriumStealer
Modifies WinLogon for persistence
Modifies Windows Defender DisableAntiSpyware settings
Modifies Windows Defender TamperProtection settings
UAC bypass
Malware Config
C2 Extraction:
91.92.42.94:1052
https://api.telegram.org/bot8851116034:AAEyleV0VCo3PXiQw0URdIA8sbkMMXtkiQA/sendDocument
Unpacked files
SH256 hash:
364d3883e81da01bb449083552e5f1526ec734bdf40b27e71a4670fc3df12e76
MD5 hash:
65c3aa0a48027921f2f94df9fd45c422
SHA1 hash:
e2a6ffb0fe3813eeda24cef74fe77f9c24714a40
SH256 hash:
ff95571a4b3880be2807cad8875ee6ccd0b2b705caf0d4d0d0f56950dd78ee5a
MD5 hash:
6295c384c45ef898b40608f7af8155db
SHA1 hash:
75111839c370518271e1b625f506062f7ab31c3a
Detections:
triage_plugx_rat
SH256 hash:
9036d0cc3ea5a4a944f60cc40f6968e3fa52371f5ecc6ee036eb1e796f9b4a2a
MD5 hash:
1ccf058adad37081a1911512171052ea
SHA1 hash:
71e8f4fed4f00e83e1f0a086c0ccb35ffa251869
SH256 hash:
b0f79f8878cd47726f21b9210e7020595614e8126be44bd5cd656e6d44f5706b
MD5 hash:
29c928a8f3170366bbdf51b501d2bc83
SHA1 hash:
36492b1829b28431277d48c252ab9bcc9a7165ff
Detections:
triage_plugx_rat
SH256 hash:
b649e05ddb07c6517190a5440544dbe950daae1fbf21e920beb274f88eccc19a
MD5 hash:
aadbdd46aa5a82ff266a85e059306f18
SHA1 hash:
fc8da7d4125ad65c55a59045fd0c4d6f9654a569
Detections:
win_masslogger_w0
SH256 hash:
e78d5803e91b613d2cfdd05ee4d40e938b01e43c8a954d0f8774c35b8bc49ed2
MD5 hash:
3cb002bc0a0bc805032ae1f79da20568
SHA1 hash:
9eb46925627cef34fa45cbd1aec6ec009f1bc492
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments