| File name: | DOCUMENTO PDF CON LA INFORMACIO_N DE LA AUDIENCIA PROGRAMADA 20 DE AGOSTO DE 2025.zip |
| Full analysis: | https://app.any.run/tasks/0ec1f63b-affe-462c-8302-aa619015d3a1 |
| Verdict: | Malicious activity |
| Threats: | XWorm is a remote access trojan (RAT) sold as a malware-as-a-service. It possesses an extensive hacking toolset and is capable of gathering private information and files from the infected computer, hijacking MetaMask and Telegram accounts, and tracking user activity. XWorm is typically delivered to victims' computers through multi-stage attacks that start with phishing emails. |
| Analysis date: | September 03, 2025, 16:51:57 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=deflate |
| MD5: | 60A149983F56882899E2CC560866A082 |
| SHA1: | 265CD9DF4849568C5349CF1D5FFBFEABCFD05556 |
| SHA256: | 18DCADCB23C6CE71E36EDFDEFE76683C1538DBFAE80FE6959A3207AA75C86982 |
| SSDEEP: | 98304:Q3k0WWgmXL1xuQ8bYUDOyJ1yVNIigMT2+OjkvHmzOPPLJIQsCeo/7hqdE/zklW+E:ig6pek/ |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | 0x0009 |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2025:02:07 01:15:42 |
| ZipCRC: | 0xfe3830ba |
| ZipCompressedSize: | 129205 |
| ZipUncompressedSize: | 190528 |
| ZipFileName: | DOCUMENTO PDF CON LA INFORMACION DE LA AUDIENCIA PROGRAMADA 20 DE AGOSTO DE 2025.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 440 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb3148.46564\DOCUMENTO PDF CON LA INFORMACIÓN DE LA AUDIENCIA PROGRAMADA 20 DE AGOSTO DE 2025.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXb3148.46564\DOCUMENTO PDF CON LA INFORMACIÓN DE LA AUDIENCIA PROGRAMADA 20 DE AGOSTO DE 2025.exe | WinRAR.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: IIS Express Worker Process Exit code: 4294967295 Version: 10.0.26013.1000 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 536 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1488 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb3148.4269\DOCUMENTO PDF CON LA INFORMACIÓN DE LA AUDIENCIA PROGRAMADA 20 DE AGOSTO DE 2025.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXb3148.4269\DOCUMENTO PDF CON LA INFORMACIÓN DE LA AUDIENCIA PROGRAMADA 20 DE AGOSTO DE 2025.exe | WinRAR.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: IIS Express Worker Process Exit code: 4294967295 Version: 10.0.26013.1000 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2628 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | DOCUMENTO PDF CON LA INFORMACIÓN DE LA AUDIENCIA PROGRAMADA 20 DE AGOSTO DE 2025.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3148 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\DOCUMENTO PDF CON LA INFORMACIO_N DE LA AUDIENCIA PROGRAMADA 20 DE AGOSTO DE 2025.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.91.0 Modules
| |||||||||||||||
| 3976 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | DOCUMENTO PDF CON LA INFORMACIÓN DE LA AUDIENCIA PROGRAMADA 20 DE AGOSTO DE 2025.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3980 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | DOCUMENTO PDF CON LA INFORMACIÓN DE LA AUDIENCIA PROGRAMADA 20 DE AGOSTO DE 2025.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4884 | "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | DOCUMENTO PDF CON LA INFORMACIÓN DE LA AUDIENCIA PROGRAMADA 20 DE AGOSTO DE 2025.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: AddInProcess.exe Version: 4.8.9037.0 built by: NET481REL1 Modules
XWorm(PID) Process(4884) AddInProcess32.exe C2213.209.150.144:2483 Keys AES<666666> Options Splitter<Xwormmm> Sleep time1 USB drop name1008554884 MutexVtEVkTI3knul8lGs | |||||||||||||||
| 5400 | "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | — | DOCUMENTO PDF CON LA INFORMACIÓN DE LA AUDIENCIA PROGRAMADA 20 DE AGOSTO DE 2025.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: AddInProcess.exe Exit code: 0 Version: 4.8.9037.0 built by: NET481REL1 Modules
| |||||||||||||||
| 6488 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb3148.49076\DOCUMENTO PDF CON LA INFORMACIÓN DE LA AUDIENCIA PROGRAMADA 20 DE AGOSTO DE 2025.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXb3148.49076\DOCUMENTO PDF CON LA INFORMACIÓN DE LA AUDIENCIA PROGRAMADA 20 DE AGOSTO DE 2025.exe | WinRAR.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: IIS Express Worker Process Exit code: 4294967295 Version: 10.0.26013.1000 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (3148) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3148) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3148) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\preferences.zip | |||
| (PID) Process: | (3148) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
| (PID) Process: | (3148) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
| (PID) Process: | (3148) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\DOCUMENTO PDF CON LA INFORMACIO_N DE LA AUDIENCIA PROGRAMADA 20 DE AGOSTO DE 2025.zip | |||
| (PID) Process: | (3148) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3148) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3148) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3148) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3148 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb3148.46564\IISEXPRESSHELPER.dll | executable | |
MD5:28E63EEDE0FF9401E868882E28D95592 | SHA256:7D0E515957ED60771CA017985AE0C43A9262247DE789F40EAC84EA00F4C0D3C2 | |||
| 3148 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb3148.46564\IISUTIL2.dll | executable | |
MD5:7746FE4D290DB237DB88260B3F550B63 | SHA256:A23DFD32AED17E8423589A74E48453442678D972D1FD3D4CDAA1EA41EB35D76F | |||
| 440 | DOCUMENTO PDF CON LA INFORMACIÓN DE LA AUDIENCIA PROGRAMADA 20 DE AGOSTO DE 2025.exe | C:\Users\admin\getTitleGetRuntimeMethodsStringToHGlobalAuto\IISEXPRESSHELPER.dll | executable | |
MD5:28E63EEDE0FF9401E868882E28D95592 | SHA256:7D0E515957ED60771CA017985AE0C43A9262247DE789F40EAC84EA00F4C0D3C2 | |||
| 440 | DOCUMENTO PDF CON LA INFORMACIÓN DE LA AUDIENCIA PROGRAMADA 20 DE AGOSTO DE 2025.exe | C:\Users\admin\getTitleGetRuntimeMethodsStringToHGlobalAuto\rtinfo.dll | executable | |
MD5:B69B0513774A58E805AA15C03EA82B25 | SHA256:825C20AA5036605CB9C96870D81E1B052D1AB54ADF6595BF604EBC2B400EE08B | |||
| 3148 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb3148.49076\DOCUMENTO PDF CON LA INFORMACIÓN DE LA AUDIENCIA PROGRAMADA 20 DE AGOSTO DE 2025.exe | executable | |
MD5:B0D39CE242699383FBE4CF1F16B53719 | SHA256:01FCAFF363713CECD482D9ECF99814FC83870871B82A62BF11AB43D8844A8281 | |||
| 4884 | AddInProcess32.exe | C:\Users\admin\AppData\Local\Temp\Log.tmp | text | |
MD5:093330741218F376298C6F967A6A5C61 | SHA256:D053A1CB90D3C340E8F0E606BCB808A05A1DA2A80384411192B45529172DECE7 | |||
| 3148 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb3148.49076\IISEXPRESSHELPER.dll | executable | |
MD5:28E63EEDE0FF9401E868882E28D95592 | SHA256:7D0E515957ED60771CA017985AE0C43A9262247DE789F40EAC84EA00F4C0D3C2 | |||
| 3148 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb3148.49076\nativrd2.dll | executable | |
MD5:8AE813C940BB9EA0E1031E229822DDA6 | SHA256:794686BA1B4F568E281B95814BEB31B12E205C8CB49853D831D650B528A6DB56 | |||
| 3148 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb3148.49076\rtinfo.dll | executable | |
MD5:B69B0513774A58E805AA15C03EA82B25 | SHA256:825C20AA5036605CB9C96870D81E1B052D1AB54ADF6595BF604EBC2B400EE08B | |||
| 3148 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DIb3148.3348\IISUTIL2.dll | executable | |
MD5:7746FE4D290DB237DB88260B3F550B63 | SHA256:A23DFD32AED17E8423589A74E48453442678D972D1FD3D4CDAA1EA41EB35D76F | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6540 | svchost.exe | GET | 200 | 23.203.176.221:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
1268 | svchost.exe | GET | 200 | 23.197.202.231:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
1268 | svchost.exe | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
5188 | SIHClient.exe | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
5188 | SIHClient.exe | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
2940 | svchost.exe | GET | 200 | 72.246.169.163:80 | http://x1.c.lencr.org/ | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
5944 | MoUsoCoreWorker.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1268 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2992 | RUXIMICS.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6540 | svchost.exe | 40.126.31.69:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6540 | svchost.exe | 23.203.176.221:80 | ocsp.digicert.com | AKAMAI-AS | US | whitelisted |
1268 | svchost.exe | 23.197.202.231:80 | crl.microsoft.com | Akamai International B.V. | US | whitelisted |
1268 | svchost.exe | 88.221.169.152:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
5944 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
4884 | AddInProcess32.exe | Misc Attack | ET DROP Spamhaus DROP Listed Traffic Inbound group 61 |
4884 | AddInProcess32.exe | Malware Command and Control Activity Detected | REMOTE [ANY.RUN] Xworm TCP Packet |