Want More XWorm?, (Wed, Mar 4th)
ID: a5cc0313-b5bb-53c0-9a4c-e13b714036b5
STIX ID: report--a5cc0313-b5bb-53c0-9a4c-e13b714036b5
Feed Name: SANS ISC Diary
Threat Score
The report describes a recent wave of XWorm (Win.XWorm) infections: attackers use obfuscated JavaScript to drop PowerShell loaders which decode and run an XOR-encrypted DLL that performs process hollowing to inject the XWorm client. The author includes the extracted configuration (C2 IP, mutex, AES key, install filename), file SHA256 IOCs, and notes reuse of a previously observed C2 address.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
