🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b68004143749042690a482d394eec376d6c0fad6ae034e2e7a817a562f0ca0fc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



XWorm


Vendor detections: 9


Intelligence 9 IOCs YARA 4 File information Comments

SHA256 hash: b68004143749042690a482d394eec376d6c0fad6ae034e2e7a817a562f0ca0fc
SHA3-384 hash: 755082585434220d7f7d562a3db476d3877af64ca009121bb1c0377960a92d6607d56ef2b615711dcddc2f0b8998e096
SHA1 hash: 5ca1980a63cc6fd7be0f555028c79caa0854bd7c
MD5 hash: 13e071096bb855cbe3ad86f984e003e5
humanhash: lion-oxygen-winter-oscar
File name:NewXOrderXRequest_20205081017PM.TAR
Download: download sample
Signature XWorm
File size:69'469 bytes
First seen:2026-05-20 18:08:42 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 1536:aqqt57W2eEIN51fbKwF4gE3Dp5+dcW56P4k/LawMb3IMf:VqPXINfbKwF4gyDp5+uPpjaJ33f
TLSH T1616302B37E78A7BBF2A97B8591540C02D4ABCF5C7B4217366C1D2054E4D60D900EAF5E
Magika zip
Reporter TomU
Tags:xworm zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
39
Origin country :
CH CH
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:New Order Request_20205081017PM.js
File size:111'688 bytes
SHA256 hash: 6c3656bdf000df5e357a6997f9b1a34a993487d1f102b43fb5cf0bb405ee1d04
MD5 hash: 1bc74f16447fddb2902f7ce4fb1c811e
MIME type:text/plain
Signature XWorm
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.9%
Tags:
ransomware shell sage
Result
Verdict:
Malicious
File Type:
JS File - Malicious
Behaviour
BlacklistAPI detected
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm base64 cmd evasive fingerprint lolbin masquerade obfuscated obfuscated powershell powershell repaired timeout timeout
Verdict:
Malicious
File Type:
zip
First seen:
2025-08-21T03:15:00Z UTC
Last seen:
2025-08-29T16:18:00Z UTC
Hits:
~100
Gathering data
Threat name:
Script-JS.Packed.Generic
Status:
Suspicious
First seen:
2025-08-21 14:42:00 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
19 of 38 (50.00%)
Threat level:
  1/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Base64_Encoded_Powershell_Directives
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

XWorm

zip b68004143749042690a482d394eec376d6c0fad6ae034e2e7a817a562f0ca0fc

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments