MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 76f71c718f9238d746ac3ad7f80e8d69e5e853eb5c3afbb0ab2550212093de1d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
XWorm
Vendor detections: 16
| SHA256 hash: | 76f71c718f9238d746ac3ad7f80e8d69e5e853eb5c3afbb0ab2550212093de1d |
|---|---|
| SHA3-384 hash: | e736b52a6ae60e136766cbedd01b4104d6385c8d2c8cda383b1a342f7efbdf1ff3df665647517d1033664f0ab77a7049 |
| SHA1 hash: | 7f9cbdac02ec5a35b7e70ba234eafcbfd9558b50 |
| MD5 hash: | 098b0fce4e52a2dfb1174d9828680633 |
| humanhash: | california-beryllium-neptune-mobile |
| File name: | z.exe |
| Download: | download sample |
| Signature | XWorm |
| File size: | 39'405'568 bytes |
| First seen: | 2025-10-12 17:50:16 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (49'246 x AgentTesla, 20'506 x Formbook, 12'374 x SnakeKeylogger) |
| ssdeep | 786432:By1kRqcED//5lKz8PcVAgJS6Rckjw/SJ26fQ4nGh:BZyr/5lKz8PcVjLjw/82DcG |
| TLSH | T10587AC7310D59BA268188C2D76DA7D59BD46BC02C948D9B0B2C75C9EBE443B36F2CB13 |
| TrID | 75.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.9% (.EXE) Win64 Executable (generic) (10522/11/4) 4.6% (.EXE) Win32 Executable (generic) (4504/4/1) 2.1% (.ICL) Windows Icons Library (generic) (2059/9) 2.1% (.EXE) OS/2 Executable (generic) (2029/13) |
| Magika | pebin |
| Reporter | |
| Tags: | exe xworm |
Indicators Of Compromise (IOCs)
Below is a list of indicators of compromise (IOCs) associated with this malware samples.
| IOC | ThreatFox Reference |
|---|---|
| 192.169.69.26:8887 | https://threatfox.abuse.ch/ioc/1612970/ |
| 8.208.101.138:10272 | https://threatfox.abuse.ch/ioc/1612972/ |
Intelligence
File Origin
NLVendor Threat Intelligence
Result
Behaviour
Result
Signature
Behaviour
Result
Behaviour
Malware Config
172.245.106.45:1122
xxxxz-61067.portmap.host:61067
omnizplsr-22653.portmap.host:22653
remdefrem.duckdns.org:1515
:1515
188.240.81.202:1607
13.62.18.15:1607
refrech.duckdns.org:7777
196.251.71.73:1177
rockyx22.duckdns.org:8887
1.tcp.sa.ngrok.io:21424
77.100.63.251:5631
taxlogs.linkpc.net:7000
premiemclient-4570.work.gd:7000
petro4prime.ydns.eu:5909
107.175.214.47:5555
OAjoWtc1G9RInLp0gJZzfw==:33
196.251.70.87:2799
91.92.242.128:7000
sigmaratohio-52009.portmap.host:55615
faris552-36484.portmap.host:36484
82.24.40.117:7000
170.205.31.12:4886
ddnsservice01.theworkpc.com:7000
185.209.20.25:443
185.196.10.190:8000
45.88.9.209:5063
epicskillforge.com:443
wealthyblessed.minhaempresa.tv:3033
exim111.casacam.net:7978
88.218.17.152:7978
bore.pub:3977
160.238.13.158:30121
191.96.225.192:8080
winservicesconsole.duckdns.org:7001
103.245.164.58:5045
192.159.99.205:7000
xworm7000.duckdns.org:7000
172.111.136.37:6000
196.251.70.152:5000
unknownhk1.duckdns.org:8080
96.44.154.196:7000
154.12.89.173:7000
refrech.duckdns.org:2805
duskesthostplug.duckdns.org:1111
nonoise.duckdns.org:6065
143.14.44.192:999
fuckrat.ru:1131
31.57.97.59:505
1.tcp.eu.cpolar.io:10272
82.26.74.222:162
W0rmLeFilou-26308.portmap.host:26308
176.97.210.95:6000
qrpn9be.localto.net:2810
localhost:4782
87.97.126.177:4782
91.92.242.148:1070
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | Any_SU_Domain |
|---|---|
| Author: | you |
| Description: | Detect any reference to .su domains or subdomains |
| Rule name: | AutoIT_Compiled |
|---|---|
| Author: | @bartblaze |
| Description: | Identifies compiled AutoIT script (as EXE). This rule by itself does NOT necessarily mean the detected file is malicious. |
| Rule name: | ByteCode_MSIL_Backdoor_AsyncRAT |
|---|---|
| Author: | ReversingLabs |
| Description: | Yara rule that detects AsyncRAT backdoor. |
| Rule name: | cobalt_strike_tmp01925d3f |
|---|---|
| Author: | The DFIR Report |
| Description: | files - file ~tmp01925d3f.exe |
| Reference: | https://thedfirreport.com |
| Rule name: | command_and_control |
|---|---|
| Author: | CD_R0M_ |
| Description: | This rule searches for common strings found by malware using C2. Based on a sample used by a Ransomware group |
| Rule name: | CP_Script_Inject_Detector |
|---|---|
| Author: | DiegoAnalytics |
| Description: | Detects attempts to inject code into another process across PE, ELF, Mach-O binaries |
| Rule name: | DebuggerCheck__API |
|---|---|
| Reference: | https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara |
| Rule name: | DebuggerCheck__MemoryWorkingSet |
|---|---|
| Author: | Fernando Mercês |
| Description: | Anti-debug process memory working set size check |
| Reference: | http://www.gironsec.com/blog/2015/06/anti-debugger-trick-quicky/ |
| Rule name: | DebuggerCheck__QueryInfo |
|---|---|
| Reference: | https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara |
| Rule name: | DebuggerCheck__RemoteAPI |
|---|---|
| Reference: | https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara |
| Rule name: | DebuggerException__SetConsoleCtrl |
|---|---|
| Reference: | https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara |
| Rule name: | DetectEncryptedVariants |
|---|---|
| Author: | Zinyth |
| Description: | Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded |
| Rule name: | DetectGoMethodSignatures |
|---|---|
| Author: | Wyatt Tauber |
| Description: | Detects Go method signatures in unpacked Go binaries |
| Rule name: | Detect_Golang_Binary |
|---|---|
| Author: | Andrew Morrow |
| Description: | Detects binaries compiled with Go |
| Rule name: | Detect_Go_GOMAXPROCS |
|---|---|
| Author: | Obscurity Labs LLC |
| Description: | Detects Go binaries by the presence of runtime.GOMAXPROCS in the runtime metadata |
| Rule name: | Detect_PowerShell_Obfuscation |
|---|---|
| Author: | daniyyell |
| Description: | Detects obfuscated PowerShell commands commonly used in malicious scripts. |
| Rule name: | Disable_Defender |
|---|---|
| Author: | iam-py-test |
| Description: | Detect files disabling or modifying Windows Defender, Windows Firewall, or Microsoft Smartscreen |
| Rule name: | EXE_RAT_XWorm_April2024 |
|---|---|
| Author: | Yashraj Solanki - Cyber Threat Intelligence Analyst at Bridewell |
| Rule name: | FreddyBearDropper |
|---|---|
| Author: | Dwarozh Hoshiar |
| Description: | Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip. |
| Rule name: | GoBinTest |
|---|
| Rule name: | golang |
|---|
| Rule name: | Golangmalware |
|---|---|
| Author: | Dhanunjaya |
| Description: | Malware in Golang |
| Rule name: | golang_binary_string |
|---|---|
| Description: | Golang strings present |
| Rule name: | golang_bin_JCorn_CSC846 |
|---|---|
| Author: | Justin Cornwell |
| Description: | CSC-846 Golang detection ruleset |
| Rule name: | golang_duffcopy_amd64 |
|---|
| Rule name: | HiveRansomware |
|---|---|
| Author: | Dhanunjaya |
| Description: | Yara Rule To Detect Hive V4 Ransomware |
| Rule name: | Indicator_MiniDumpWriteDump |
|---|---|
| Author: | Obscurity Labs LLC |
| Description: | Detects PE files and PowerShell scripts that use MiniDumpWriteDump either through direct imports or string references |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_NoneWindowsUA |
|---|---|
| Author: | ditekSHen |
| Description: | Detects Windows executables referencing non-Windows User-Agents |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_TelegramChatBot |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables using Telegram Chat Bot |
| Rule name: | MALWARE_Win_AsyncRAT |
|---|---|
| Author: | ditekSHen |
| Description: | Detects AsyncRAT |
| Rule name: | MALWARE_Win_R77 |
|---|---|
| Author: | ditekSHen |
| Description: | Detects r77 rootkit |
| Rule name: | MALWARE_Win_XWorm |
|---|---|
| Author: | ditekSHen |
| Description: | Detects XWorm |
| Rule name: | Multifamily_RAT_Detection |
|---|---|
| Author: | Lucas Acha (http://www.lukeacha.com) |
| Description: | Generic Detection for multiple RAT families, PUPs, Packers and suspicious executables |
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | NETexecutableMicrosoft |
|---|---|
| Author: | malware-lu |
| Rule name: | Njrat |
|---|---|
| Author: | botherder https://github.com/botherder |
| Description: | Njrat |
| Rule name: | pe_detect_tls_callbacks |
|---|
| Rule name: | PE_Digital_Certificate |
|---|---|
| Author: | albertzsigovits |
| Rule name: | pe_imphash |
|---|
| Rule name: | ProgramLanguage_Golang |
|---|---|
| Author: | albertzsigovits |
| Description: | Application written in Golang programming language |
| Rule name: | RANSOMWARE |
|---|---|
| Author: | ToroGuitar |
| Rule name: | SEH__vectored |
|---|---|
| Reference: | https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara |
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
| Rule name: | Suspicious_PssCaptureSnapshot_Usage |
|---|---|
| Author: | Dana Behling - Just me not for personal curiosity, no company. |
| Description: | Detects binaries abusing PssCaptureSnapshot in combination with typical combination that indicates malicious activity. |
| Rule name: | SUSP_DOTNET_PE_List_AV |
|---|---|
| Author: | SECUINFRA Falcon Team |
| Description: | Detecs .NET Binary that lists installed AVs |
| Rule name: | Sus_CMD_Powershell_Usage |
|---|---|
| Author: | XiAnzheng |
| Description: | May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP) |
| Rule name: | telegram_bot_api |
|---|---|
| Author: | rectifyq |
| Description: | Detects file containing Telegram Bot API |
| Rule name: | ThreadControl__Context |
|---|---|
| Reference: | https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara |
| Rule name: | TH_Generic_MassHunt_Webshells_2025_CYFARE |
|---|---|
| Author: | CYFARE |
| Description: | Generic multi-language webshell mass-hunt rule (PHP/ASP(X)/JSP/Python/Perl/Node) - 2025 |
| Reference: | https://cyfare.net/ |
| Rule name: | Windows_Rootkit_R77_d0367e28 |
|---|---|
| Author: | Elastic Security |
| Reference: | https://www.elastic.co/security-labs/elastic-security-labs-steps-through-the-r77-rootkit |
| Rule name: | Windows_Trojan_XWorm_b7d6eaa8 |
|---|---|
| Author: | Elastic Security |
| Rule name: | win_xworm_bytestring |
|---|---|
| Author: | Matthew @ Embee_Research |
| Description: | Detects bytestring present in unobfuscated xworm |
| Rule name: | win_xworm_simple_strings |
|---|---|
| Author: | Matthew @ Embee_Research |
| Description: | Detects simple strings present in unobfuscated xworm |
| Rule name: | win_xworm_w0 |
|---|---|
| Author: | jeFF0Falltrades |
| Description: | Detects win.xworm. |
| Rule name: | xworm |
|---|---|
| Author: | jeFF0Falltrades |
| Rule name: | xworm_kingrat |
|---|---|
| Author: | jeFF0Falltrades |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.