🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for md5_hash 34e90568af4dcd40f4f04174ec326e2a.

Database Entry


IOC ID:1764240
IOC: 34e90568af4dcd40f4f04174ec326e2a
IOC Type :md5_hash
Threat Type :payload
Malware: XWorm
Confidence Level : Confidence level is high (100%)
Is compromised? : False
First seen:2026-03-13 06:13:55 UTC
Last seen:never
UUID:a22d56fa-1e75-11f1-9af6-42010aa4000a
Reporter Lenny_3BO
Reward 5 credits from ThreatFox
Tags:Loader process-hollowing trojanized-library XWorm

Avatar
Lenny_3BO
Stage 3 .NET loader (extracted_assembly.bin / TaskScheduler.dll). Trojanized dahall/taskscheduler v2.12.2.0 with 205 injected malicious namespaces. Contains: HackForums.gigajew.Mandark RunPE process hollowing, 6-vector WMI VM detection (VirtualMachineDetector), CMSTP UAC bypass with CorpVPN INF template, 3 persistence mechanisms. ConfuserEx obfuscated. Portuguese debug strings indicate Brazilian developer.