MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d32a7182a7dc9c2170610201cc3833932e38705ca3beb6a5e8a73e62db0ce91a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



XWorm


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: d32a7182a7dc9c2170610201cc3833932e38705ca3beb6a5e8a73e62db0ce91a
SHA3-384 hash: 007eb4baca3c41aaaa8e73abb6b1c4aaf9123144c5ac846521d34e64b5de818c148140aaa2fa9b3c354a317f278bb85f
SHA1 hash: 363f8f432f90aff944409d5bc1296462df57afbe
MD5 hash: 5431e42c5b801d58655ad42932c5f376
humanhash: social-fish-don-earth
File name:Reckless Driver photos Cam7 August 27 2026.JS
Download: download sample
Signature XWorm
File size:3'473'811 bytes
First seen:2026-08-27 08:18:57 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 98304:hh2CDAnwJwnD9FlE0MefXilETEhveAUfVdzDYfZDDzJCv:hh2CAawDh2ETEh2YfK
TLSH T178F54E8E0341503B7D69E72FF1B65D26DA061987958AFF1AB03C42143BB5AD31338EE6
Magika javascript
Reporter abuse_ch
Tags:js xworm

Intelligence


File Origin
# of uploads :
1
# of downloads :
131
Origin country :
SE SE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
js
First seen:
2026-08-27T03:29:00Z UTC
Last seen:
2026-08-27T05:13:00Z UTC
Hits:
~10
Result
Threat name:
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
Antivirus detection for dropped file
Hides threads from debuggers
JavaScript source code contains functionality to generate code involving a shell, file or stream
Multi AV Scanner detection for submitted file
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sigma detected: WScript or CScript Dropper
Suricata IDS alerts for network traffic
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Unusual module load detection (module proxying)
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Yara detected XWorm
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1964580 Sample: Reckless Driver photos Cam7... Startdate: 27/08/2026 Architecture: WINDOWS Score: 100 40 keyauth.win 2->40 46 Suricata IDS alerts for network traffic 2->46 48 Multi AV Scanner detection for submitted file 2->48 50 Yara detected XWorm 2->50 52 2 other signatures 2->52 9 wscript.exe 1 2->9         started        signatures3 process4 signatures5 54 Windows Scripting host queries suspicious COM object (likely to drop second stage) 9->54 12 MOFMFMQSBESWUOSJ.PIF 2 6 9->12         started        process6 dnsIp7 42 107.174.20.215, 49711, 8824 NEXEON-NexeonTechnologiesIncUS United States 12->42 56 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 12->56 58 Tries to steal Mail credentials (via file / registry access) 12->58 60 Tries to harvest and steal browser information (history, passwords, etc) 12->60 62 2 other signatures 12->62 16 MOFMFMQSBESWUOSJ.PIF.exe 12->16         started        19 csc.exe 4 12->19         started        22 csc.exe 3 12->22         started        24 3 other processes 12->24 signatures8 process9 file10 44 Antivirus detection for dropped file 16->44 38 C:\Users\user\...\MOFMFMQSBESWUOSJ.PIF.exe, PE32 19->38 dropped 26 conhost.exe 19->26         started        28 cvtres.exe 1 19->28         started        30 conhost.exe 22->30         started        32 cvtres.exe 1 22->32         started        34 conhost.exe 24->34         started        36 cvtres.exe 1 24->36         started        signatures11 process12
Gathering data
Gathering data
Result
Malware family:
Score:
  10/10
Tags:
family:xworm defense_evasion discovery execution pyinstaller rat spyware stealer trojan upx
Behaviour
Kills process with taskkill
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Command and Scripting Interpreter: PowerShell
Detects Pyinstaller
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of NtSetInformationThreadHideFromDebugger
UPX packed file
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Reads user/profile data of web browsers
Detect Xworm Payload
Family: Xworm
Malware Config
C2 Extraction:
107.174.20.215:8824
ctiYLZFGjvYtfEzjZbLveA==:23
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments