General

  • Target

    EXM Free Tweaking Utility V8.3 LEAKED 2025.bat

  • Size

    671KB

  • Sample

    250508-y7rgtsxnx3

  • MD5

    483423f13894ad21cd9c37a2a5adae19

  • SHA1

    fe6bb76d64a8df56318db98c3fc9c471bacaa82c

  • SHA256

    1c9ed30b893b83b29d285cc8b37bdba353ab18dab8288e44a367162fb536c609

  • SHA512

    5f050acfcedbaf60bde9c0e028a7685a520e284ca17cd0b52c28a94dde75948324bc0738a5ba965ca26e39e55c6861af63bef23546af2b074a7940e329e719c6

  • SSDEEP

    3072:uGzQbmbkAqA2xH7VkKEn14IZVvisLur+K3:uGiVNEn14IZVvisL43

Malware Config

Extracted

Family

xworm

Attributes
  • Install_directory

    %ProgramData%

  • install_file

    svchost.exe

  • pastebin_url

    https://pastebin.com/raw/ZnhxAV6a

  • telegram

    https://api.telegram.org/bot7564421410:AAHgBw2xu-96C8rVIiibt59lzDnMAPliOm4/sendMessage?chat_id=7741783264

Extracted

Family

asyncrat

Botnet

Default

C2

127.0.0.1:6606

127.0.0.1:7707

127.0.0.1:8808

https://api.telegram.org/bot7564421410:AAHgBw2xu-96C8rVIiibt59lzDnMAPliOm4/sendMessage?chat_id=7741783264

Mutex

AsyncMutex_6SI8OkPnk

Attributes
  • delay

    3

  • install

    false

  • install_folder

    %AppData%

aes.plain

Extracted

Family

gurcu

C2

https://api.telegram.org/bot7564421410:AAHgBw2xu-96C8rVIiibt59lzDnMAPliOm4/sendMessage?chat_id=7741783264

Targets

    • Target

      EXM Free Tweaking Utility V8.3 LEAKED 2025.bat

    • Size

      671KB

    • MD5

      483423f13894ad21cd9c37a2a5adae19

    • SHA1

      fe6bb76d64a8df56318db98c3fc9c471bacaa82c

    • SHA256

      1c9ed30b893b83b29d285cc8b37bdba353ab18dab8288e44a367162fb536c609

    • SHA512

      5f050acfcedbaf60bde9c0e028a7685a520e284ca17cd0b52c28a94dde75948324bc0738a5ba965ca26e39e55c6861af63bef23546af2b074a7940e329e719c6

    • SSDEEP

      3072:uGzQbmbkAqA2xH7VkKEn14IZVvisLur+K3:uGiVNEn14IZVvisL43

    • AsyncRat

      AsyncRAT is designed to remotely monitor and control other computers written in C#.

    • Asyncrat family

    • Deletes Windows Defender Definitions

      Uses mpcmdrun utility to delete all AV definitions.

    • Detect Xworm Payload

    • Gurcu family

    • Gurcu, WhiteSnake

      Gurcu aka WhiteSnake is a malware stealer written in C#.

    • StormKitty

      StormKitty is an open source info stealer written in C#.

    • StormKitty payload

    • Stormkitty family

    • Xworm

      Xworm is a remote access trojan written in C#.

    • Xworm family

    • Async RAT payload

    • Command and Scripting Interpreter: PowerShell

      Using powershell.exe command.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Clipboard Data

      Adversaries may collect data stored in the clipboard from users copying information within or between applications.

    • Executes dropped EXE

    • Loads dropped DLL

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Unsecured Credentials: Credentials In Files

      Steal credentials from unsecured files.

    • Accesses cryptocurrency files/wallets, possible credential harvesting

    • Adds Run key to start application

    • Drops desktop.ini file(s)

    • Legitimate hosting services abused for malware hosting/C2

    • Looks up external IP address via web service

      Uses a legitimate IP lookup service to find the infected system's external IP.

    • Looks up geolocation information via web service

      Uses a legitimate geolocation service to find the infected system's geolocation info.

    • Obfuscated Files or Information: Command Obfuscation

      Adversaries may obfuscate content during command execution to impede detection.

    • Enumerates processes with tasklist

    • Suspicious use of NtSetInformationThreadHideFromDebugger

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Enterprise v16

Tasks

OSZAR »