File name:

sewi.exe

Full analysis: https://app.any.run/tasks/958db82a-0726-4fc5-851e-54f2dc696ddd
Verdict: Malicious activity
Threats:

XWorm is a remote access trojan (RAT) sold as a malware-as-a-service. It possesses an extensive hacking toolset and is capable of gathering private information and files from the infected computer, hijacking MetaMask and Telegram accounts, and tracking user activity. XWorm is typically delivered to victims' computers through multi-stage attacks that start with phishing emails.

Analysis date: March 26, 2026, 16:53:31
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
iqvw64-sys
vuln-driver
procexp-sys
xworm
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

22885F81A98018DCDB4D8198664C82E2

SHA1:

418C0116785CEF14B0D63EC5D902A3E9FD19DFE4

SHA256:

47E63F7B23F5B2DC490C963CFCCF55904755C16707B0DDB63B4E4897B98F5824

SSDEEP:

98304:ZO3PROr/2OpvlkoCdqJncwoXRGs0/cojR0B2sM3G22kHvZ5aavo86efEjavo86eC:UBnQ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Vulnerable driver has been detected

      • sDQ0X.exe (PID: 7636)
    • XWORM has been detected (YARA)

      • XClient.exe (PID: 4316)
  • SUSPICIOUS

    • Reads the date of Windows installation

      • Sewi.exe (PID: 7712)
      • sewi.exe (PID: 5384)
    • Drops a system driver (possible attempt to evade defenses)

      • sDQ0X.exe (PID: 7636)
      • Sewi.exe (PID: 7712)
    • Creates or modifies Windows services

      • sDQ0X.exe (PID: 7636)
  • INFO

    • Checks supported languages

      • sewi.exe (PID: 5384)
      • sDQ0X.exe (PID: 7636)
      • Sewi.exe (PID: 7712)
      • XClient.exe (PID: 4316)
    • Create files in a temporary directory

      • sDQ0X.exe (PID: 7636)
    • Reads the machine GUID from the registry

      • sDQ0X.exe (PID: 7636)
      • sewi.exe (PID: 5384)
      • XClient.exe (PID: 4316)
    • Reads the computer name

      • sewi.exe (PID: 5384)
      • XClient.exe (PID: 4316)
      • Sewi.exe (PID: 7712)
    • Creates files or folders in the user directory

      • sewi.exe (PID: 5384)
    • Reads security settings of Internet Explorer

      • sewi.exe (PID: 5384)
      • Sewi.exe (PID: 7712)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

XWorm

(PID) Process(4316) XClient.exe
C2 (1)127.0.0.1:7000
Keys
AES<123456789>
Options
Splitter<Xwormmm>
Sleep time3
USB drop nameXWorm V5.6
MutexWgrvdCIZr7YbjX4n
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (63.1)
.exe | Win64 Executable (generic) (23.8)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)
.exe | Generic Win/DOS Executable (1.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2026:03:26 16:21:07+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 11
CodeSize: 2229248
InitializedDataSize: 2048
UninitializedDataSize: -
EntryPoint: 0x22228e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
FileDescription:
FileVersion: 1.0.0.0
InternalName: sewi.exe
LegalCopyright:
OriginalFileName: sewi.exe
ProductVersion: 1.0.0.0
AssemblyVersion: 1.0.0.0
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
140
Monitored processes
8
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start sewi.exe no specs #XWORM xclient.exe no specs sewi.exe no specs sewi.exe slui.exe conhost.exe no specs THREAT sdq0x.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
204\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exesDQ0X.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2652"C:\Users\admin\AppData\Roaming\Sewi.exe" C:\Users\admin\AppData\Roaming\Sewi.exesewi.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\roaming\sewi.exe
c:\windows\system32\ntdll.dll
4136C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4316"C:\Users\admin\AppData\Roaming\XClient.exe" C:\Users\admin\AppData\Roaming\XClient.exe
sewi.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\roaming\xclient.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
XWorm
(PID) Process(4316) XClient.exe
C2 (1)127.0.0.1:7000
Keys
AES<123456789>
Options
Splitter<Xwormmm>
Sleep time3
USB drop nameXWorm V5.6
MutexWgrvdCIZr7YbjX4n
5384"C:\Users\admin\Desktop\sewi.exe" C:\Users\admin\Desktop\sewi.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\sewi.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
7636"C:\WINDOWS\SoftwareDistribution\Download\sDQ0X.exe" -map C:\WINDOWS\SoftwareDistribution\Download\hOogK.sysC:\Windows\SoftwareDistribution\Download\sDQ0X.exe
Sewi.exe
User:
admin
Company:
UG North
Integrity Level:
HIGH
Description:
Kernel Driver Utility
Exit code:
0
Version:
1.0.0.2002
Modules
Images
c:\windows\softwaredistribution\download\sdq0x.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
7712"C:\Users\admin\AppData\Roaming\Sewi.exe" C:\Users\admin\AppData\Roaming\Sewi.exe
sewi.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\roaming\sewi.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
7876\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSewi.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
7 526
Read events
7 500
Write events
24
Delete events
2

Modification events

(PID) Process:(5384) sewi.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(5384) sewi.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(5384) sewi.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(5384) sewi.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(4136) slui.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\3d\52C64B7E
Operation:writeName:@%SystemRoot%\System32\sppcomapi.dll,-3200
Value:
Software Licensing
(PID) Process:(7636) sDQ0X.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NalDrv
Operation:writeName:ImagePath
Value:
\??\C:\Users\admin\Desktop\NalDrv.sys
(PID) Process:(7636) sDQ0X.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PROCEXP152
Operation:writeName:ErrorControl
Value:
1
(PID) Process:(7636) sDQ0X.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PROCEXP152
Operation:writeName:Type
Value:
1
(PID) Process:(7636) sDQ0X.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PROCEXP152
Operation:writeName:Start
Value:
3
(PID) Process:(7636) sDQ0X.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PROCEXP152
Operation:writeName:ImagePath
Value:
\??\C:\Users\admin\AppData\Local\Temp\PROCEXP152.sys
Executable files
0
Suspicious files
0
Text files
0
Unknown types
6

Dropped files

PID
Process
Filename
Type
7712Sewi.exeC:\Windows\SoftwareDistribution\Download\hOogK.sysbinary
MD5:657C2A27E4038AE1041474FB901540FA
SHA256:19066DF50EB8B7C76D06552CCBD6248A6384A45A7F04500C6DE4AB37149BAC54
5384sewi.exeC:\Users\admin\AppData\Roaming\Sewi.exebinary
MD5:2CA19D0F12D1F16F6D08B34C48593826
SHA256:29BDF43AF7FCE4A48A4699F01BA35A9D23EC72109F9A8D59B84788610066B715
5384sewi.exeC:\Users\admin\AppData\Roaming\XClient.exebinary
MD5:E1E562D474FB6FA1A728EB98CD903E26
SHA256:9EA44A571244B57D5F8FF3CF3410974247F6D15C335F3681599F401B99E3F0C0
7712Sewi.exeC:\Windows\SoftwareDistribution\Download\sDQ0X.exebinary
MD5:083C6C05AC5875D0B6E997E894CA07BC
SHA256:03AEFD40698CAFBD48138784F362FB9A36F726FB50F262CA40695729F7B553CA
7636sDQ0X.exeC:\Users\admin\Desktop\NalDrv.sysbinary
MD5:1898CEDA3247213C084F43637EF163B3
SHA256:4429F32DB1CC70567919D7D47B844A91CF1329A6CD116F582305F3B7B60CD60B
7636sDQ0X.exeC:\Users\admin\AppData\Local\Temp\PROCEXP152.sysbinary
MD5:C06DDA757B92E79540551EFD00B99D4B
SHA256:9B6A84F7C40EA51C38CC4D2E93EFB3375E9D98D4894A85941190D94FBE73A4E4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
21
DNS requests
10
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
680
svchost.exe
GET
200
95.100.102.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
US
binary
814 b
whitelisted
5276
MoUsoCoreWorker.exe
GET
200
95.100.102.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
US
binary
814 b
whitelisted
680
svchost.exe
GET
200
23.216.77.8:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
4136
slui.exe
POST
500
48.192.1.65:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
US
text
512 b
whitelisted
3280
svchost.exe
GET
200
95.100.102.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Update%20Signing%20CA%202.3.crl
US
binary
813 b
whitelisted
3280
svchost.exe
GET
200
95.100.102.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Signing%20CA%202.3.crl
US
binary
400 b
whitelisted
4136
slui.exe
POST
500
48.192.1.65:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
US
text
512 b
whitelisted
3280
svchost.exe
GET
200
95.100.102.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Signing%20CA%202.2.crl
US
binary
401 b
whitelisted
3280
svchost.exe
GET
200
23.216.77.30:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
NL
binary
824 b
whitelisted
3280
svchost.exe
GET
200
95.100.102.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl
US
binary
814 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
680
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
5276
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
92.123.104.52:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
8124
slui.exe
48.192.1.65:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
680
svchost.exe
23.216.77.8:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
680
svchost.exe
95.100.102.101:80
www.microsoft.com
AKAMAI-AS
US
whitelisted
5276
MoUsoCoreWorker.exe
95.100.102.101:80
www.microsoft.com
AKAMAI-AS
US
whitelisted
5276
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
whitelisted
www.bing.com
  • 92.123.104.52
  • 92.123.104.50
  • 92.123.104.45
  • 92.123.104.39
  • 92.123.104.30
  • 92.123.104.29
  • 92.123.104.47
  • 92.123.104.37
  • 92.123.104.26
whitelisted
activation-v2.sls.microsoft.com
  • 48.192.1.65
whitelisted
google.com
  • 142.251.110.102
  • 142.251.110.139
  • 142.251.110.100
  • 142.251.110.138
  • 142.251.110.113
  • 142.251.110.101
whitelisted
crl.microsoft.com
  • 23.216.77.8
  • 23.216.77.20
  • 23.216.77.19
  • 23.216.77.30
  • 23.216.77.36
  • 23.216.77.38
  • 23.216.77.42
  • 23.216.77.28
  • 23.216.77.18
  • 23.216.77.35
  • 23.216.77.15
  • 23.216.77.6
  • 23.216.77.22
whitelisted
www.microsoft.com
  • 95.100.102.101
whitelisted
self.events.data.microsoft.com
  • 13.89.179.11
whitelisted

Threats

No threats detected
No debug info