MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 e5720090ad89883afd9444c7330e7fd0fe37403b2fc66fe6709e56a57f0938d2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
XWorm
Vendor detections: 6
| SHA256 hash: | e5720090ad89883afd9444c7330e7fd0fe37403b2fc66fe6709e56a57f0938d2 |
|---|---|
| SHA3-384 hash: | cf81f3be0ec360bf76c60b864fa7b230a53d8801923aef61027633b8e7302a29fb1a54dacddc08629400d75ed6c092ce |
| SHA1 hash: | c38a64c11538ae2206e64852fbf3ae897770596a |
| MD5 hash: | 391ed6003e6c86968292dc8ac9733cf1 |
| humanhash: | monkey-leopard-spring-maine |
| File name: | rfq.arj |
| Download: | download sample |
| Signature | XWorm |
| File size: | 2'904 bytes |
| First seen: | 2026-07-21 11:20:33 UTC |
| Last seen: | Never |
| File type: | arj |
| MIME type: | application/x-rar |
| ssdeep | 48:zl87+VWjSNx0W0qf8StJGVW8o7pqw5FkTog9pawIxIdE+RTcrsb08tt:zlDVWjSNxjxeVeBOp2x0RTcrsb08tt |
| TLSH | T15D513B53F1A7560EF1CC8C3E375BE2120495225FFB77548B5E4CA9E174D80226B05153 |
| TrID | 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1) 38.4% (.RAR) RAR compressed archive (gen) (5000/1) |
| Magika | rar |
| Reporter | |
| Tags: | arj Downloader js malspam rar xworm |
Intelligence
File Origin
# of uploads :
1
# of downloads :
172
Origin country :
DEFile Archive Information
This file archive contains 1 file(s), sorted by their relevance:
| File name: | RFQ 6000223205.js |
|---|---|
| File size: | 2'263'888 bytes |
| SHA256 hash: | cb7561e369f812da9398570e5b4851040deee1ef9fd236394d2cd3a0ce356026 |
| MD5 hash: | 6dca6e421a358a9f275a682bd4b5b20c |
| MIME type: | text/plain |
| Signature | XWorm |
Vendor Threat Intelligence
Verdict:
Malicious
Score:
94.9%
Tags:
autorun keylog shell blic
Verdict:
Malicious
File Type:
rar
First seen:
2026-07-21T05:51:00Z UTC
Last seen:
2026-07-22T07:52:00Z UTC
Hits:
~10
Threat name:
Win32.Trojan.Egairtigado
Status:
Malicious
First seen:
2026-07-21 11:22:09 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
14 of 38 (36.84%)
Threat level:
5/5
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
0.85
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
XWorm
arj e5720090ad89883afd9444c7330e7fd0fe37403b2fc66fe6709e56a57f0938d2
(this sample)
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.