🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8afccdede322e2e39f92fdf769cb62f50b0db775a500e941cc77b170a7d8b015. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



XWorm


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: 8afccdede322e2e39f92fdf769cb62f50b0db775a500e941cc77b170a7d8b015
SHA3-384 hash: a16ad8b3d72e6e60011b0c55550a1d2959b290eef593b7e1d8a521caf23b95785a76ec08be193d397197c2cf679a16c1
SHA1 hash: 3ea730200c753091a02a05327d46e19d50b1be54
MD5 hash: 67d400eadce80b392059bccc3988f92d
humanhash: music-delta-sixteen-nuts
File name:PO# SD90_N_67563_NU8E_SPEC.JS
Download: download sample
Signature XWorm
File size:8'812'094 bytes
First seen:2026-05-08 10:30:33 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 196608:bRTCrD1bSKY6GwgGMpiUsVChdaQw0m4CamDdxF8viC555JLrc0f9ZVGwpwkEh3D/:bRurD1bSKY62pDsMhdaQwd4C5P8viC5W
TLSH T1A6965A85530D867E3756EF4D127AC9E0A98E21A65ACACB15700ED274B60DC83E3CF4DB
Magika javascript
Reporter abuse_ch
Tags:js xworm

Intelligence


File Origin
# of uploads :
1
# of downloads :
131
Origin country :
SE SE
Vendor Threat Intelligence
No detections
Gathering data
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
aes base64 base64 crypto evasive lolbin obfuscated obfuscated persistence powershell privilege reconnaissance repaired schtasks zusy
Verdict:
Malicious
File Type:
js
First seen:
2026-05-08T01:50:00Z UTC
Last seen:
2026-05-10T08:44:00Z UTC
Hits:
~1000
Detections:
PDM:Trojan.Win32.Generic Backdoor.Agent.TCP.C&C Trojan.JS.SAgent.sb HEUR:Trojan.Script.Generic HEUR:Trojan.PowerShell.Tesre.sb
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
60 / 100
Signature
Found potential dummy code loops (likely to delay analysis)
JavaScript source code contains functionality to generate code involving a shell, file or stream
Multi AV Scanner detection for submitted file
Sigma detected: WScript or CScript Dropper
Behaviour
Behavior Graph:
Gathering data
Threat name:
Script-JS.Trojan.Qwexlafiba
Status:
Malicious
First seen:
2026-05-08 05:54:18 UTC
File Type:
Binary
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:xworm discovery execution persistence rat trojan
Behaviour
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
Program crash
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Command and Scripting Interpreter: PowerShell
Looks up external IP address via web service
Checks computer location settings
Detect Xworm Payload
Family: Xworm
Malware Config
C2 Extraction:
204.10.160.250:7007
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments