s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-939a602b569d795a1bebace69b1f41843a5deb49f67fecb8b3a55dfea69524f4 high

📛 Threat Title

XWorm: COMUNICACIÓN URGENTE CAMBIO DE MEDIDA.js

Category: XWorm Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: js. Size: 60824 bytes. Tags: js, XWorm. Reporter: smica83. First seen: 2026-09-25 10:18:53.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 939a602b569d795a1bebace69b1f41843a5deb49f67fecb8b3a55dfea69524f4 VT 6 / 75

IOC database

Type
hash_sha256
Value
939a602b569d795a1bebace69b1f41843a5deb49f67fecb8b3a55dfea69524f4
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
XWorm

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 6 of 75 VirusTotal vendors

VendorVerdictDetection
huorong malicious SVM:TrojanDownloader/JS.MalBehav.gen!D
Kaspersky malicious HEUR:Trojan.Script.SAgent.gen
Kingsoft malicious Script.Trojan.SAgent.gen
McAfeeD malicious ti!939A602B569D
Microsoft malicious Trojan:Script/Wacatac.B!ml
Symantec malicious XSNet.Heur!gen16

Details From VirusTotal

Basic Properties
MD5f88753bca78133ec113f3a92a0f07d24
SHA-135e1cc8983929d98cf6e8c9ad9c95ef1cb638a2f
SHA-256939a602b569d795a1bebace69b1f41843a5deb49f67fecb8b3a55dfea69524f4
SSDEEP768:7woJ9SoFMwXcOc4FJekp0KTKtdl+LFd5vwFi3AhiFzGWmy+vJMoZ:yeeQd86wdZ
TLSHT1C9534143C39BCC08B270A1D4D60AF11F99A48D6274F59887A169E5DEFBBC824D06F6F1
File typeJavaScript
File type tagjavascript
File extensionjs
MagicASCII text, with CRLF, LF line terminators
File size59.4 KB
History
First seen on VirusTotal2026-09-24 17:29 UTC
Last submission2026-09-25 18:14 UTC
Last analysis2026-09-25 11:17 UTC
Last modified on VirusTotal2026-09-26 01:14 UTC
Known Names
  • COMUNICACIÓN URGENTE CAMBIO DE MEDIDA.js
  • yr01fuum.exe
  • NOTIFICACIÓN PERSONAL ADMISIÓN DE DEMANDA Y ESTADO N° 098.js
  • XXX.js
hash_sha1 35e1cc8983929d98cf6e8c9ad9c95ef1cb638a2f VT 6 / 75

IOC database

Type
hash_sha1
Value
35e1cc8983929d98cf6e8c9ad9c95ef1cb638a2f
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 6 of 75 VirusTotal vendors

VendorVerdictDetection
huorong malicious SVM:TrojanDownloader/JS.MalBehav.gen!D
Kaspersky malicious HEUR:Trojan.Script.SAgent.gen
Kingsoft malicious Script.Trojan.SAgent.gen
McAfeeD malicious ti!939A602B569D
Microsoft malicious Trojan:Script/Wacatac.B!ml
Symantec malicious XSNet.Heur!gen16

Details From VirusTotal

Basic Properties
MD5f88753bca78133ec113f3a92a0f07d24
SHA-135e1cc8983929d98cf6e8c9ad9c95ef1cb638a2f
SHA-256939a602b569d795a1bebace69b1f41843a5deb49f67fecb8b3a55dfea69524f4
SSDEEP768:7woJ9SoFMwXcOc4FJekp0KTKtdl+LFd5vwFi3AhiFzGWmy+vJMoZ:yeeQd86wdZ
TLSHT1C9534143C39BCC08B270A1D4D60AF11F99A48D6274F59887A169E5DEFBBC824D06F6F1
File typeJavaScript
File type tagjavascript
File extensionjs
MagicASCII text, with CRLF, LF line terminators
File size59.4 KB
History
First seen on VirusTotal2026-09-24 17:29 UTC
Last submission2026-09-25 18:14 UTC
Last analysis2026-09-25 11:17 UTC
Last modified on VirusTotal2026-09-26 01:14 UTC
Known Names
  • COMUNICACIÓN URGENTE CAMBIO DE MEDIDA.js
  • yr01fuum.exe
  • NOTIFICACIÓN PERSONAL ADMISIÓN DE DEMANDA Y ESTADO N° 098.js
  • XXX.js
hash_md5 f88753bca78133ec113f3a92a0f07d24 VT 6 / 75

IOC database

Type
hash_md5
Value
f88753bca78133ec113f3a92a0f07d24
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 6 of 75 VirusTotal vendors

VendorVerdictDetection
huorong malicious SVM:TrojanDownloader/JS.MalBehav.gen!D
Kaspersky malicious HEUR:Trojan.Script.SAgent.gen
Kingsoft malicious Script.Trojan.SAgent.gen
McAfeeD malicious ti!939A602B569D
Microsoft malicious Trojan:Script/Wacatac.B!ml
Symantec malicious XSNet.Heur!gen16

Details From VirusTotal

Basic Properties
MD5f88753bca78133ec113f3a92a0f07d24
SHA-135e1cc8983929d98cf6e8c9ad9c95ef1cb638a2f
SHA-256939a602b569d795a1bebace69b1f41843a5deb49f67fecb8b3a55dfea69524f4
SSDEEP768:7woJ9SoFMwXcOc4FJekp0KTKtdl+LFd5vwFi3AhiFzGWmy+vJMoZ:yeeQd86wdZ
TLSHT1C9534143C39BCC08B270A1D4D60AF11F99A48D6274F59887A169E5DEFBBC824D06F6F1
File typeJavaScript
File type tagjavascript
File extensionjs
MagicASCII text, with CRLF, LF line terminators
File size59.4 KB
History
First seen on VirusTotal2026-09-24 17:29 UTC
Last submission2026-09-25 18:14 UTC
Last analysis2026-09-25 11:17 UTC
Last modified on VirusTotal2026-09-26 01:14 UTC
Known Names
  • COMUNICACIÓN URGENTE CAMBIO DE MEDIDA.js
  • yr01fuum.exe
  • NOTIFICACIÓN PERSONAL ADMISIÓN DE DEMANDA Y ESTADO N° 098.js
  • XXX.js

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: js. Size: 60824 bytes. Tags: js, XWorm. Reporter: smica83. First seen: 2026-09-25 10:18:53.

Remediations (10)

  • web:advisory.eventussecurity.com

    A malicious campaign has been identified that abuses the paste.ee service to deliver remote access trojans like XWorm and AsyncRAT. It began with a seemingly corrupted JavaScript file filled with random Unicode characters.

  • web:blog.netmanageit.com

    Organizations compromised by XWorm V6 face not only immediate data loss but also long‐term exposure to espionage, ransomware, and secondary infections orchestrated by follow‐on payloads. 6. Strategies for Detection and Mitigation Defending against XWorm V6 requires a blend of proactive and reactive controls.

  • web:cybersecuritynews.com

    XWorm injects shellcode into these processes while simultaneously hooking various Windows APIs to hide its presence and maintain stealth operations. This comprehensive approach to system manipulation represents a significant evolution in RAT capabilities, requiring equally sophisticated detection and mitigation strategies from security teams.

  • web:darkwebinformer.com

    📖 Overview An IOC has been flagged involving the abuse of the official Telegram Bot API as a command-and-control (C2) channel for the XWormmalware family. This method leverages Telegram infrastructure to evade detection by blending malicious traffic with legitimate encrypted communications. Confidence is assessed at 50%.

  • web:gurucul.com

    Technical analysis of XWorm v7 RAT infection chain, C2 encryption, plugins, MITRE mapping, IOCs, and detection guidance for SOC teams.

  • web:vercel.com

    Next.js uses an internal x-middleware-subrequest header to detect and prevent recursion—and bypass the execution of Middleware. Middleware happens separately from the rendering process of a page.

  • web:www.csirtasobancaria.com

    Durante actividades de monitoreo realizadas por el equipo de analistas del Csirt Financiero, se observó una reciente campaña del troyano de acceso remoto XWorm que utiliza correos electrónicos de facturación para inducir al usuario a abrir un archivo Visual Basic Script adjunto.

  • web:www.huntress.com

    XWorm is a particularly nasty remote access trojan (RAT) that gives attackers the keys to your kingdom. This malware is designed to sneak onto systems, steal everything from credentials to cryptocurrency, and give threat actors full control.

  • web:www.securonix.com

    Discover the MEME#4CHAN phishing campaign's use of meme-filled code and techniques to deliver Xworm payloads, including attack chain and mitigation .

  • web:www.threatanatomy.com

    En este artículo, exploramos cómo XWorm se reporta a sus creadores, así como cómo obtiene nuevas variantes de si mismo.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.