MB-939a602b569d795a1bebace69b1f41843a5deb49f67fecb8b3a55dfea69524f4
high
📛 Threat Title
XWorm: COMUNICACIÓN URGENTE CAMBIO DE MEDIDA.js
Description
File type: js. Size: 60824 bytes. Tags: js, XWorm. Reporter: smica83. First seen: 2026-09-25 10:18:53.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
939a602b569d795a1bebace69b1f41843a5deb49f67fecb8b3a55dfea69524f4
VT 6 / 75
IOC database
- Type
- hash_sha256
- Value
939a602b569d795a1bebace69b1f41843a5deb49f67fecb8b3a55dfea69524f4- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- XWorm
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 6 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| huorong | malicious | SVM:TrojanDownloader/JS.MalBehav.gen!D |
| Kaspersky | malicious | HEUR:Trojan.Script.SAgent.gen |
| Kingsoft | malicious | Script.Trojan.SAgent.gen |
| McAfeeD | malicious | ti!939A602B569D |
| Microsoft | malicious | Trojan:Script/Wacatac.B!ml |
| Symantec | malicious | XSNet.Heur!gen16 |
Details From VirusTotal
Basic Properties
| MD5 | f88753bca78133ec113f3a92a0f07d24 |
| SHA-1 | 35e1cc8983929d98cf6e8c9ad9c95ef1cb638a2f |
| SHA-256 | 939a602b569d795a1bebace69b1f41843a5deb49f67fecb8b3a55dfea69524f4 |
| SSDEEP | 768:7woJ9SoFMwXcOc4FJekp0KTKtdl+LFd5vwFi3AhiFzGWmy+vJMoZ:yeeQd86wdZ |
| TLSH | T1C9534143C39BCC08B270A1D4D60AF11F99A48D6274F59887A169E5DEFBBC824D06F6F1 |
| File type | JavaScript |
| File type tag | javascript |
| File extension | js |
| Magic | ASCII text, with CRLF, LF line terminators |
| File size | 59.4 KB |
History
| First seen on VirusTotal | 2026-09-24 17:29 UTC |
| Last submission | 2026-09-25 18:14 UTC |
| Last analysis | 2026-09-25 11:17 UTC |
| Last modified on VirusTotal | 2026-09-26 01:14 UTC |
Known Names
COMUNICACIÓN URGENTE CAMBIO DE MEDIDA.jsyr01fuum.exeNOTIFICACIÓN PERSONAL ADMISIÓN DE DEMANDA Y ESTADO N° 098.jsXXX.js
hash_sha1
35e1cc8983929d98cf6e8c9ad9c95ef1cb638a2f
VT 6 / 75
IOC database
- Type
- hash_sha1
- Value
35e1cc8983929d98cf6e8c9ad9c95ef1cb638a2f- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 6 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| huorong | malicious | SVM:TrojanDownloader/JS.MalBehav.gen!D |
| Kaspersky | malicious | HEUR:Trojan.Script.SAgent.gen |
| Kingsoft | malicious | Script.Trojan.SAgent.gen |
| McAfeeD | malicious | ti!939A602B569D |
| Microsoft | malicious | Trojan:Script/Wacatac.B!ml |
| Symantec | malicious | XSNet.Heur!gen16 |
Details From VirusTotal
Basic Properties
| MD5 | f88753bca78133ec113f3a92a0f07d24 |
| SHA-1 | 35e1cc8983929d98cf6e8c9ad9c95ef1cb638a2f |
| SHA-256 | 939a602b569d795a1bebace69b1f41843a5deb49f67fecb8b3a55dfea69524f4 |
| SSDEEP | 768:7woJ9SoFMwXcOc4FJekp0KTKtdl+LFd5vwFi3AhiFzGWmy+vJMoZ:yeeQd86wdZ |
| TLSH | T1C9534143C39BCC08B270A1D4D60AF11F99A48D6274F59887A169E5DEFBBC824D06F6F1 |
| File type | JavaScript |
| File type tag | javascript |
| File extension | js |
| Magic | ASCII text, with CRLF, LF line terminators |
| File size | 59.4 KB |
History
| First seen on VirusTotal | 2026-09-24 17:29 UTC |
| Last submission | 2026-09-25 18:14 UTC |
| Last analysis | 2026-09-25 11:17 UTC |
| Last modified on VirusTotal | 2026-09-26 01:14 UTC |
Known Names
COMUNICACIÓN URGENTE CAMBIO DE MEDIDA.jsyr01fuum.exeNOTIFICACIÓN PERSONAL ADMISIÓN DE DEMANDA Y ESTADO N° 098.jsXXX.js
hash_md5
f88753bca78133ec113f3a92a0f07d24
VT 6 / 75
IOC database
- Type
- hash_md5
- Value
f88753bca78133ec113f3a92a0f07d24- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 6 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| huorong | malicious | SVM:TrojanDownloader/JS.MalBehav.gen!D |
| Kaspersky | malicious | HEUR:Trojan.Script.SAgent.gen |
| Kingsoft | malicious | Script.Trojan.SAgent.gen |
| McAfeeD | malicious | ti!939A602B569D |
| Microsoft | malicious | Trojan:Script/Wacatac.B!ml |
| Symantec | malicious | XSNet.Heur!gen16 |
Details From VirusTotal
Basic Properties
| MD5 | f88753bca78133ec113f3a92a0f07d24 |
| SHA-1 | 35e1cc8983929d98cf6e8c9ad9c95ef1cb638a2f |
| SHA-256 | 939a602b569d795a1bebace69b1f41843a5deb49f67fecb8b3a55dfea69524f4 |
| SSDEEP | 768:7woJ9SoFMwXcOc4FJekp0KTKtdl+LFd5vwFi3AhiFzGWmy+vJMoZ:yeeQd86wdZ |
| TLSH | T1C9534143C39BCC08B270A1D4D60AF11F99A48D6274F59887A169E5DEFBBC824D06F6F1 |
| File type | JavaScript |
| File type tag | javascript |
| File extension | js |
| Magic | ASCII text, with CRLF, LF line terminators |
| File size | 59.4 KB |
History
| First seen on VirusTotal | 2026-09-24 17:29 UTC |
| Last submission | 2026-09-25 18:14 UTC |
| Last analysis | 2026-09-25 11:17 UTC |
| Last modified on VirusTotal | 2026-09-26 01:14 UTC |
Known Names
COMUNICACIÓN URGENTE CAMBIO DE MEDIDA.jsyr01fuum.exeNOTIFICACIÓN PERSONAL ADMISIÓN DE DEMANDA Y ESTADO N° 098.jsXXX.js
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: js. Size: 60824 bytes. Tags: js, XWorm. Reporter: smica83. First seen: 2026-09-25 10:18:53.
Remediations (10)
-
web:advisory.eventussecurity.com
A malicious campaign has been identified that abuses the paste.ee service to deliver remote access trojans like XWorm and AsyncRAT. It began with a seemingly corrupted JavaScript file filled with random Unicode characters.
-
web:blog.netmanageit.com
Organizations compromised by XWorm V6 face not only immediate data loss but also long‐term exposure to espionage, ransomware, and secondary infections orchestrated by follow‐on payloads. 6. Strategies for Detection and Mitigation Defending against XWorm V6 requires a blend of proactive and reactive controls.
-
web:cybersecuritynews.com
XWorm injects shellcode into these processes while simultaneously hooking various Windows APIs to hide its presence and maintain stealth operations. This comprehensive approach to system manipulation represents a significant evolution in RAT capabilities, requiring equally sophisticated detection and mitigation strategies from security teams.
-
web:darkwebinformer.com
📖 Overview An IOC has been flagged involving the abuse of the official Telegram Bot API as a command-and-control (C2) channel for the XWormmalware family. This method leverages Telegram infrastructure to evade detection by blending malicious traffic with legitimate encrypted communications. Confidence is assessed at 50%.
-
web:gurucul.com
Technical analysis of XWorm v7 RAT infection chain, C2 encryption, plugins, MITRE mapping, IOCs, and detection guidance for SOC teams.
-
web:vercel.com
Next.js uses an internal x-middleware-subrequest header to detect and prevent recursion—and bypass the execution of Middleware. Middleware happens separately from the rendering process of a page.
-
web:www.csirtasobancaria.com
Durante actividades de monitoreo realizadas por el equipo de analistas del Csirt Financiero, se observó una reciente campaña del troyano de acceso remoto XWorm que utiliza correos electrónicos de facturación para inducir al usuario a abrir un archivo Visual Basic Script adjunto.
-
web:www.huntress.com
XWorm is a particularly nasty remote access trojan (RAT) that gives attackers the keys to your kingdom. This malware is designed to sneak onto systems, steal everything from credentials to cryptocurrency, and give threat actors full control.
-
web:www.securonix.com
Discover the MEME#4CHAN phishing campaign's use of meme-filled code and techniques to deliver Xworm payloads, including attack chain and mitigation .
-
web:www.threatanatomy.com
En este artículo, exploramos cómo XWorm se reporta a sus creadores, así como cómo obtiene nuevas variantes de si mismo.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.