🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8950267b5c8b4ac7833a5fbb48100fa3ad837a0ea7483bd86b4a7b11cc2d8996. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



XWorm


Vendor detections: 11


Intelligence 11 IOCs YARA File information Comments

SHA256 hash: 8950267b5c8b4ac7833a5fbb48100fa3ad837a0ea7483bd86b4a7b11cc2d8996
SHA3-384 hash: 2c3b02ec80602ea5a39cad0373abcb88e0245a77c4e108c5d8e3767de326d968e2f1757d8a801f7ee71f1af7451fe8e5
SHA1 hash: 51cc67b7e5a946f1466a6d05aaccbf55f0721b0a
MD5 hash: 22ab19c0f3797d8f691e2aed33f633b2
humanhash: thirteen-oven-green-quebec
File name:GraftingPlace.bat
Download: download sample
Signature XWorm
File size:68'905 bytes
First seen:2025-11-11 10:04:47 UTC
Last seen:Never
File type:Batch (bat) bat
MIME type:text/plain
ssdeep 1536:VqsvbSQ7CZzx84gzyofyRLvSFZ2SLuND6owR6oa3L:VSgwV84gmo72uuND5wsL
Threatray 2'282 similar samples on MalwareBazaar
TLSH T124635CFE66049C0744D87952DB284DCC3D68BC96D312A9B2F9BFECE37D91201BB49098
Magika batch
Reporter ShadowOpCode
Tags:/api-telegram-org--bot8024716497 bat xworm

Intelligence


File Origin
# of uploads :
1
# of downloads :
105
Origin country :
IT IT
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
PURCHASE_ORDER5001.vbs
Verdict:
Malicious activity
Analysis date:
2025-11-10 12:15:48 UTC
Tags:
github telegram susp-powershell xworm ims-api generic

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Running batch commands
Launching cmd.exe command interpreter
Creating a file
Launching a process
Сreating synchronization primitives
DNS request
Connection attempt
Sending a custom TCP request
Using the Windows Management Instrumentation requests
Connection attempt to an infection source
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
base64 evasive obfuscated powershell
Threat name:
Script-BAT.Trojan.Heuristic
Status:
Malicious
First seen:
2025-11-10 12:28:30 UTC
File Type:
Text (Batch)
AV detection:
7 of 23 (30.43%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:xworm execution rat trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: PowerShell
Legitimate hosting services abused for malware hosting/C2
Badlisted process makes network request
Detect Xworm Payload
Xworm
Xworm family
Malware Config
C2 Extraction:
31.40.204.73:1414
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

XWorm

Batch (bat) bat 8950267b5c8b4ac7833a5fbb48100fa3ad837a0ea7483bd86b4a7b11cc2d8996

(this sample)

Comments