🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f20f9194c19e9b50f8ea578acbf4dae7bb9b5d23d88239674fe94b371c811523. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments 1

SHA256 hash: f20f9194c19e9b50f8ea578acbf4dae7bb9b5d23d88239674fe94b371c811523
SHA3-384 hash: a92dd00021a3a54b7a1b4159fdff1702cb5d3c5920eb14acde85c1bb6c0c31930a021da39f23b5e5defb0697b59727aa
SHA1 hash: e1cf8deb2caa3db6b62717d47461eed9937facbc
MD5 hash: 3cade88c90e4abc782cdae114bf6badc
humanhash: juliet-sodium-harry-kilo
File name:PO-Specification.zip
Download: download sample
File size:1'552 bytes
First seen:2026-05-21 14:52:29 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24:9MRDz4ixsY4EgoE5pjLAd3ydcHGGF7onhwmP8nvlw3UeL5/+aLLAd3ni0PkVENu:9M1h2egXDAhUcFF7on38omyAhnXkVr
TLSH T17E31E7D39EE9482ED2C04F363C80251F0D3A67581034BB464C377B82AA229496E929B2
Magika zip
Reporter TomU
Tags:nnx.linkworldlogiticservices.online xworm zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
CH CH
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:PO-Specification.js
File size:6'872 bytes
SHA256 hash: 82033e82df5ec34fea2e5308532e73db491a2f6bd15bab5a0a59eb043d4b05ea
MD5 hash: 113d6902d1f8215085719277c3c7417d
MIME type:text/plain
Vendor Threat Intelligence
Verdict:
Malicious
Score:
70%
Tags:
infosteal shell
Result
Verdict:
Malicious
File Type:
JS File - Malicious
Payload URLs
URL
File name
https://cdn.marinetraffic.world/obsk/gest.exe
JS File
Behaviour
BlacklistAPI detected
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
cmd evasive lolbin repaired rundll32 taskkill taskkill timeout timeout xwizard
Verdict:
Malicious
File Type:
zip
First seen:
2024-07-16T05:31:00Z UTC
Last seen:
2024-07-16T05:43:00Z UTC
Hits:
~10
Gathering data
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2024-07-16 14:17:15 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
6 of 24 (25.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
adware defense_evasion discovery execution persistence ransomware spyware
Behaviour
Delays execution with timeout.exe
Kills process with taskkill
Modifies Internet Explorer settings
Modifies registry class
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Uses Volume Shadow Copy WMI provider
Uses Volume Shadow Copy service COM API
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
System Time Discovery
Checks computer location settings
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

zip f20f9194c19e9b50f8ea578acbf4dae7bb9b5d23d88239674fe94b371c811523

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments



Avatar
commented on 2026-05-25 14:42:06 UTC

https://www.virustotal.com/gui/file/82033e82df5ec34fea2e5308532e73db491a2f6bd15bab5a0a59eb043d4b05ea/relations
hXXps://cdn.marinetraffic[.]world/obsk/gest.exe

https://www.virustotal.com/gui/url/1b027a066e66682f29ae82e68efef3e3761034c80649c1b8e9999c1471173345/relations

https://www.virustotal.com/gui/file/6664c76fa812ee8c12dfd4d5763a29d10b66b7f3beff780ff13e67dd667e575d/community
Threat Score: 10/10
Family: • xworm
C2: • nnx.linkworldlogiticservices.online:9196
File Report:
https://tria.ge/240717-r1ageavepm

https://www.virustotal.com/gui/file/377c07fa51ac771da8561e865295744aa431138a8d1006d0f2f48108f47359cd/community
Threat Score: 10/10
Family: • xworm
C2: • nnx.linkworldlogiticservices.online:9196
File Report:
https://jaffacakes118.dev/analysis/377c07fa51ac771da8561e865295744aa431138a8d1006d0f2f48108f47359cd
https://tria.ge/240727-gnrj2szhql