MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 620b824bc1426bd64f3c0ce6fad30fb38d50a411dc70429964ed8ca65b0ff5ce. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
XWorm
Vendor detections: 7
| SHA256 hash: | 620b824bc1426bd64f3c0ce6fad30fb38d50a411dc70429964ed8ca65b0ff5ce |
|---|---|
| SHA3-384 hash: | 189319d3ce2b70748413f917f81d8f7263c135d0c6eec8422bde7e73df33d2140fdd41287fd4b74bacb559420cdde25d |
| SHA1 hash: | ea736fc29f68365aca89e2654d280af97ca68543 |
| MD5 hash: | 7ad0444c95a4d29d8d743db722812f1b |
| humanhash: | north-aspen-carbon-social |
| File name: | 073126-Purchase_OrderXs.js |
| Download: | download sample |
| Signature | XWorm |
| File size: | 872'443 bytes |
| First seen: | 2026-08-03 11:24:08 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | text/plain |
| ssdeep | 6144:27di9vAUJ8IH7UPg+uiRUmu/QuIuXgEvszF14ukkceYhGVFUQ8XEu0u78u+R4qXM:p |
| TLSH | T1AD05A7E25A5F0056C486BBC69CDDA7FF262466096C480BAD3277C6A04E0BC5D047EF7B |
| Magika | javascript |
| Reporter | |
| Tags: | js xworm |
Intelligence
File Origin
# of uploads :
1
# of downloads :
55
Origin country :
CHVendor Threat Intelligence
No detections
Detection(s):
Verdict:
Likely Malicious
Threat level:
7.5/10
Confidence:
100%
Tags:
downloader masquerade repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-07-30T21:36:00Z UTC
Last seen:
2026-08-03T07:56:00Z UTC
Hits:
~1000
Score:
17%
Verdict:
Benign
File Type:
SCRIPT
Gathering data
Threat name:
Win32.Trojan.Leonem
Status:
Malicious
First seen:
2026-07-31 03:58:15 UTC
File Type:
Binary
AV detection:
8 of 24 (33.33%)
Threat level:
5/5
Detection(s):
Suspicious file
Result
Malware family:
xworm
Score:
10/10
Tags:
family:xworm defense_evasion discovery execution persistence privilege_escalation pyinstaller rat spyware stealer trojan upx
Behaviour
Kills process with taskkill
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Command and Scripting Interpreter: PowerShell
Detects Pyinstaller
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
UPX packed file
Creates a file in the Startup directory
Executes dropped EXE
Loads dropped DLL
Reads user/profile data of web browsers
Badlisted process makes network request
Detect Xworm Payload
Family: Xworm
Process spawned unexpected child process
Malware Config
C2 Extraction:
31.57.184.10:5050
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
0.85
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.