Malware stories: Deworming the XWorm
ID: 019f95be-4d96-595d-a124-0179f9b78404
STIX ID: report--019f95be-4d96-595d-a124-0179f9b78404
Feed Name: CERT Polska
Threat Score
This report provides an in-depth technical analysis of the XWorm .NET malware family: describing multi-stage unpacking and deobfuscation, AES-based config decryption, implemented capabilities (RAT functions, keylogger, USB spreading, plugin support, DDoS and remote execution), the C2 protocol, a list of sample hashes and C2 servers, and an automated extractor to retrieve and decrypt configs for detection and threat intelligence purposes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
