MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ebdff7225dab7aab8c0dd1c18516d8ce956ab4ff98f12cd8343ca770cab7b2a8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



XWorm


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: ebdff7225dab7aab8c0dd1c18516d8ce956ab4ff98f12cd8343ca770cab7b2a8
SHA3-384 hash: 59735bfbdfd29c044195ed1f73943617f3adc63d6eacafad3d8ae663d8c9d6575fb74888daab6f09f994765eb24a5a94
SHA1 hash: dd1f3addc56848dae07d456385d0ddfc3b2c55a7
MD5 hash: b61f05563342a0ec5a22a986bf13d7a2
humanhash: single-berlin-cold-red
File name:pago.js
Download: download sample
Signature XWorm
File size:2'651'071 bytes
First seen:2026-07-23 12:49:19 UTC
Last seen:2026-07-23 13:23:55 UTC
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 96:CjIjIjIjIjIjIjIjIjIjIjIjIjIjIjIjIjIjIjIjIjIjIjIjIjIjIjIjIjIjIjI+:ZuEfK+MF6L/x9kBQJdW1
TLSH T1FFC5D9733EC2440EB25078916C58B502BBA525AF3E16BE4DB7F8A7D07101AAD150EDBF
Magika javascript
Reporter James_inthe_box
Tags:exe js xworm

Intelligence


File Origin
# of uploads :
2
# of downloads :
174
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm fingerprint powershell repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-07-22T11:23:00Z UTC
Last seen:
2026-07-23T09:26:00Z UTC
Hits:
~10000
Gathering data
Threat name:
Script-JS.Trojan.Cryxos
Status:
Malicious
First seen:
2026-07-23 00:56:56 UTC
File Type:
Binary
AV detection:
7 of 36 (19.44%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:xworm discovery execution persistence rat trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Command and Scripting Interpreter: JavaScript
Command and Scripting Interpreter: PowerShell
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Badlisted process makes network request
Detect Xworm Payload
Family: Xworm
Process spawned unexpected child process
Malware Config
C2 Extraction:
64.89.162.178:7007
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments