XWorm: Analyzing New Infection Tactics With Old Payload
ID: b8acfad2-774c-53f2-b679-483f5a15cb2b
STIX ID: report--b8acfad2-774c-53f2-b679-483f5a15cb2b
Feed Name: Seqrite Blog
This report details a multi-stage XWorm malware campaign that begins with a malicious LNK opening a decoy invoice and deploying a batch file which downloads and extracts a ZIP containing Python scripts; the script (man.py) decodes RC4/Base64-encoded shellcode, uses VirtualProtect and creates a suspended notepad.exe process to inject and execute the XWorm payload via APC. The XWorm binary includes a keylogger module (Xlogger) that records keystrokes and other activity to Local/Temp/log.txt for later exfiltration, and the report provides MD5 IOCs, detection names, and relevant MITRE ATT&CK techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
