🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7b1ae703f7b4a9e755aafbb4198d6f0b917b885dcfc0a3c720b7f4211541b2a0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



XWorm


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 7b1ae703f7b4a9e755aafbb4198d6f0b917b885dcfc0a3c720b7f4211541b2a0
SHA3-384 hash: aa672f92109631e1b5ec77b24d7dfdafc5878e35ab5a615c699fded6adb7eb1035cbb1bcfc7eb7a11f3b61c3f25141c0
SHA1 hash: ba1d5dbb719eb6b1b3e9ee41d6621dd491e33b93
MD5 hash: b3ae810b687b2038bb6cee9fe9a56e89
humanhash: mexico-equal-glucose-alpha
File name:Slip-02.rar
Download: download sample
Signature XWorm
File size:2'847 bytes
First seen:2026-07-28 14:36:03 UTC
Last seen:2026-07-29 12:15:25 UTC
File type: rar
MIME type:application/x-rar
ssdeep 48:u1QLIUFgpk3aUP0aL2fuwDQvNsZu/yfrfvOiUOIwAq5Oz6ZaiYSu7T8:w8FgUP/RMwyTfvOiBIwt5r
TLSH T1525109D7BA70E581E9EEE77103F9C6F5749104CC2A254A783B14A9B5304E014E306BBD
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Magika rar
Reporter TomU
Tags:rar xworm

Intelligence


File Origin
# of uploads :
10
# of downloads :
93
Origin country :
CH CH
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Slip-02.js
File size:1'776'995 bytes
SHA256 hash: 095bc1f68b458fac05aae349543df9de3961749561fdd48d8f1914bff0f5db9e
MD5 hash: 72ad0d3b9c263c0aa8dcc26990f794e4
MIME type:text/plain
Signature XWorm
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
rar
First seen:
2026-07-26T08:54:00Z UTC
Last seen:
2026-07-30T10:43:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
1 match(es)
Tags:
Rar Archive
Threat name:
Win32.Trojan.Egairtigado
Status:
Malicious
First seen:
2026-07-26 11:53:22 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
12 of 24 (50.00%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:xworm discovery execution persistence privilege_escalation rat trojan
Behaviour
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Command and Scripting Interpreter: PowerShell
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Creates a file in the Startup directory
Executes dropped EXE
Badlisted process makes network request
Detect Xworm Payload
Family: Xworm
Process spawned unexpected child process
Malware Config
C2 Extraction:
194.116.236.216:5005
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

XWorm

rar 7b1ae703f7b4a9e755aafbb4198d6f0b917b885dcfc0a3c720b7f4211541b2a0

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments