MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 81bd9744815f7acf70558fc789ef9a120853210cbf26440d842aa4ddca4e4a91. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



XWorm


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 81bd9744815f7acf70558fc789ef9a120853210cbf26440d842aa4ddca4e4a91
SHA3-384 hash: 68f2180518fbe496dd03dc896cbacf8cff935f92205fee71d77c1555b46c389d4f5ad2bd96ae46ffe0bce60b3df2be94
SHA1 hash: 7d4b2280cb4441db82d57a70f2e8ea70c786efc3
MD5 hash: d81b8e1584fe2358219e569232e68311
humanhash: mars-march-oranges-mexico
File name:N_53096818E202608254093UNY1001DEC.js
Download: download sample
Signature XWorm
File size:26'314'128 bytes
First seen:2026-08-26 07:48:48 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 768:szK1AqL1uy5b1MX5qAdRqRv1ut22L1bFu5AJMuXAXbXYjzK1AqL1bFu5AJMuXAX4:POJwWO
TLSH T1BC47649B56097E9A33758480D7837BB3B560476E2235C262FBC15BF0D8CC92D274EA87
Magika txt
Reporter abuse_ch
Tags:js xworm

Intelligence


File Origin
# of uploads :
1
# of downloads :
159
Origin country :
SE SE
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-08-25T20:07:00Z UTC
Last seen:
2026-08-27T06:01:00Z UTC
Hits:
~10
Result
Threat name:
n/a
Detection:
malicious
Classification:
expl.evad
Score:
92 / 100
Signature
Antivirus detection for URL or domain
Bypasses PowerShell execution policy
Creates processes via WMI
Joe Sandbox ML detected suspicious sample
Obfuscated command line found
Sigma detected: Invoke-Obfuscation CLIP+ Launcher
Sigma detected: Invoke-Obfuscation VAR+ Launcher
Sigma detected: Potential PowerShell Command Line Obfuscation
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Wscript starts Powershell (via cmd or directly)
Behaviour
Behavior Graph:
Gathering data
Gathering data
Result
Malware family:
Score:
  10/10
Tags:
family:xworm defense_evasion discovery execution pyinstaller rat spyware stealer trojan upx
Behaviour
Kills process with taskkill
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Detects Pyinstaller
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
UPX packed file
Executes dropped EXE
Loads dropped DLL
Reads user/profile data of web browsers
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Detect Xworm Payload
Family: Xworm
Process spawned unexpected child process
Malware Config
C2 Extraction:
102.220.160.143:5010
Dropper Extraction:
https://pub-ce02802067934e0eb072f69bf6427bf6.r2.dev/MSI_PROOPE.png
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments