🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e2988ff46fa33c35646ce8447f8d24ebefa42cbca16c9de9f766a81142e57f53. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



XWorm


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: e2988ff46fa33c35646ce8447f8d24ebefa42cbca16c9de9f766a81142e57f53
SHA3-384 hash: 8c61b7711df690c4f7b3adbce310b32860dec06cab2d24e73f52c5e4a7359624eb9894c6645099d11679c844e9ad80e8
SHA1 hash: e3f614ebadd08f94ef9e4ad7a073843a8323cb4e
MD5 hash: ec9f6ffef480b8a2723e92511a0a6c5d
humanhash: shade-network-illinois-oklahoma
File name:HWW.hta
Download: download sample
Signature XWorm
File size:1'010'063 bytes
First seen:2026-08-12 12:16:40 UTC
Last seen:Never
File type:HTML Application (hta) hta
MIME type:text/plain
ssdeep 384:7TKYNSYkY7YRTHY6THYkYPYNoTKYNoTx5YkYhYRYLYaYLYrYkYkY7Y95Y7YRTHYs:Kvc1
TLSH T14325A1F9228E2480D9500C30CD2E61D6AB57D24C4F692E743939F6EF2B86DED6F61C64
Magika javascript
Reporter James_inthe_box
Tags:exe hta xworm

Intelligence


File Origin
# of uploads :
1
# of downloads :
49
Origin country :
US US
Vendor Threat Intelligence
No detections
Result
Verdict:
Malicious
File Type:
HTA File - Malicious
Behaviour
BlacklistAPI detected
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
obfuscated repaired
Verdict:
Malicious
File Type:
hta
First seen:
2026-08-12T11:16:00Z UTC
Last seen:
2026-08-14T01:49:00Z UTC
Hits:
~100
Verdict:
inconclusive
YARA:
2 match(es)
Tags:
Html
Gathering data
Threat name:
Script-JS.Trojan.Malgent
Status:
Malicious
First seen:
2026-08-12 17:31:11 UTC
File Type:
Binary
AV detection:
7 of 24 (29.17%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:xworm collection discovery execution rat trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
outlook_office_path
outlook_win_path
Command and Scripting Interpreter: PowerShell
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Accesses Microsoft Outlook profiles
Executes dropped EXE
Badlisted process makes network request
Detect Xworm Payload
Family: Xworm
Process spawned unexpected child process
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments