🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ddda9c07172ebab38145233dbb84aca3848e85a75bb9a22ffb016f2c8105e3cc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



XWorm


Vendor detections: 6


Intelligence 6 IOCs YARA 5 File information Comments

SHA256 hash: ddda9c07172ebab38145233dbb84aca3848e85a75bb9a22ffb016f2c8105e3cc
SHA3-384 hash: ad56478d2b9d1aab016b76341b96dc03e5480329d63f3b29144f2d56043c2672c22d3b2c72ea3c6b0d6283724b969173
SHA1 hash: a90884153f866022335a978c20c4205deb116a03
MD5 hash: aa57672a65af425712b3cef7bcce744e
humanhash: paris-vegan-five-batman
File name:PurcaseOrder_pdf.iso
Download: download sample
Signature XWorm
File size:378'880 bytes
First seen:2026-05-21 14:47:34 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 3072:/HpxQKCuN6NT/d2Lu8m3EnQgB/SIngEBr6ee1mN/gWo5HmQ3Xh/7e0UMmqRXp:3QKCSs0nQg5SITd6e/IHPnhHGg
TLSH T1BF8463EC351460D7FD19167B6613B484CFA0788FA248C6DEA34C3A7E62B6570EE61D32
TrID 88.5% (.NULL) null bytes (2048000/1)
11.0% (.HTP) HomeLab/BraiLab Tape image (256000/1)
0.2% (.ATN) Photoshop Action (5007/6/1)
0.1% (.ISO) ISO 9660 CD image (2545/36/1)
0.0% (.BIN/MACBIN) MacBinary 1 (1033/5)
Magika iso
Reporter TomU
Tags:iso xworm

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
CH CH
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:PurcaseOrder pdf.js
File size:316'470 bytes
SHA256 hash: ecc3c0443a721ec9b931f98046ff74132ed13bf04b64d23372179eb0f6ac5187
MD5 hash: c59ec09c72d2a7e7aec7d4a6f5e16911
MIME type:text/plain
Signature XWorm
Vendor Threat Intelligence
Malware configuration found for:
Archives
Details
Archives
extracted archive contents
Verdict:
Malicious
File Type:
iso
First seen:
2024-08-08T21:49:00Z UTC
Last seen:
2026-05-20T02:59:00Z UTC
Hits:
~100
Gathering data
Threat name:
Script-JS.Trojan.XWorm
Status:
Malicious
First seen:
2024-08-09 11:44:46 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
19 of 36 (52.78%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
execution
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
Checks computer location settings
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_AgentTesla_Stage_1
Author:SECUINFRA Falcon Team
Description:Detects the first stage of AgentTesla (JavaScript)
Reference:https://bazaar.abuse.ch/sample/bd257d674778100639b298ea35550bf3bcb8b518978c502453e9839846f9bbec/
Rule name:SUSP_EXE_in_ISO
Author:SECUINFRA Falcon Team
Description:Detects ISO files that contains an Exe file. Does not need to be malicious
Reference:Internal Research
Rule name:SUSP_obfuscated_JS_obfuscatorio
Author:@imp0rtp3
Description:Detect JS obfuscation done by the js obfuscator (often malicious)
Reference:https://obfuscator.io

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

XWorm

iso ddda9c07172ebab38145233dbb84aca3848e85a75bb9a22ffb016f2c8105e3cc

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments