🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a128970a6df8b4be74fcd09a2a957b66b59f52618a2aedf2179b772df120c55f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



XWorm


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: a128970a6df8b4be74fcd09a2a957b66b59f52618a2aedf2179b772df120c55f
SHA3-384 hash: 1c74574099ee09c1338ab56d4f75918de7bb6d57cd36f299387c3501436dac63cc889c07de31e1853f57272ce597cd6a
SHA1 hash: 619cc8c453c97b104f54027ced830014e60e1835
MD5 hash: 7a14b68f8bdc5e562e38ca6fdbdedc64
humanhash: minnesota-hydrogen-oranges-nitrogen
File name:Slip-01.lzh.rar
Download: download sample
Signature XWorm
File size:2'966 bytes
First seen:2026-07-28 14:36:06 UTC
Last seen:2026-07-29 12:15:23 UTC
File type: rar
MIME type:application/x-rar
ssdeep 48:j2pUTRDowC+uDGIYVivaewq79TSH8WSien6zmgXig1X2xRO15O0+wewJOjQnoHbO:ju4aGrivHpBWSi26KgXig1Xe0DORekK
TLSH T1B0514A369FA4654EF88601B42D8D51FE618FA6BF4E4EDC50F57AF32F5492B29E112800
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Magika rar
Reporter TomU
Tags:rar xworm

Intelligence


File Origin
# of uploads :
10
# of downloads :
91
Origin country :
CH CH
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Slip-01.js
File size:2'815'043 bytes
SHA256 hash: 6b722e265cf3a9e6071e871583c7ba22f721f3f36e4086e46539678badd6dc81
MD5 hash: fd4f205d91d6c81e7b7728e3bda42b97
MIME type:text/plain
Signature XWorm
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
rar
First seen:
2026-07-26T08:54:00Z UTC
Last seen:
2026-07-30T10:43:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
1 match(es)
Tags:
Rar Archive
Threat name:
Win32.Trojan.Sonbokli
Status:
Malicious
First seen:
2026-07-26 11:53:00 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
10 of 38 (26.32%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:xworm collection discovery execution persistence privilege_escalation rat trojan
Behaviour
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
outlook_office_path
outlook_win_path
Command and Scripting Interpreter: JavaScript
Command and Scripting Interpreter: PowerShell
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Accesses Microsoft Outlook profiles
Creates a file in the Startup directory
Executes dropped EXE
Badlisted process makes network request
Detect Xworm Payload
Family: Xworm
Process spawned unexpected child process
Malware Config
C2 Extraction:
194.116.236.216:5005
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

XWorm

rar a128970a6df8b4be74fcd09a2a957b66b59f52618a2aedf2179b772df120c55f

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments