Wednesday, March 26, 2025

XWorm Unmasked: Weaponizing Script Obfuscation and Modern Evasion Techniques

 


Summary

 

The XWorm malware family is known for leveraging VBScript (VBS), Batch (BAT), and PowerShell (PS1) scripts to implement advanced obfuscation and evasion techniques, which are highly modular and weaponizing, and it is also a sophisticated RAT.

 

 

Technique analysis

 

Sample md5 a2907290e94d10d566afaad71f0a77d2

Sha256

ecb6c26329c5aa711c857bb37431b6d5037b0d28818af4c033c78231d007bb40

 

combining Script-based obfuscation (VBS/BAT/PS1) and multi-stages

This malware sample uses VBScript to create a batch file, WordDoc.bat. The file WordDoc.bat runs and injects and executes injection code, which is the PowerShell script, and finally uses the PS1 to load a malicious embedded payload and connects to the attacker’s Command & Control (C2) server. The way belongs to multi-stages to load the payload of attacking.

Fig.1 Combining VBS+BAT+PS1 and multi-stages

 

In VBScript, the %randomCharacters% like %uejji% is not a built-in feature—it’s a placeholder for a variable name. Typically, the attackers split malicious code into parts and reassemble them dynamically to avoid static detection. And the injection code to disable AMSI scanning and malicious payload connecting to the Command & Control (C2) server will write to the batch file.

Fig.2 embedded injection code and XClient

 

In Batch, the %randomCharacters% like %ltc% are used by the malicious code; they can be seen everywhere, and intentionally disrupting the order of variables and finally reordering PowerShell script to avoid static detection. And “setlocal enabledelayedexpansion” a legitimate feature for handling variables dynamically, but attackers abuse it for obfuscation to do delayed expansion, along with detection and mitigation strategies. Split malicious commands into parts and reassemble them at runtime using !var! delayed expansion. Finally, we can see the PowerShell strings are long strings encoded by base64 to avoid static detection.

Fig.3 using !var! delayed expansion

 

In PowerShell, the first thing to do is to read the injection string from the batch file and to decode it with base64 and then to execute the injection code. It uses byte arrays instead of strings to evade signature-based detection; here, it uses amsi.dll to disable AMSI scanning, allowing malware to execute undetected. It is ready for the next step to continue to execute another malicious code.

Fig.4 disable AMSI scanning

 

And the below PowerShell script is performing advanced memory manipulation to disable Windows Event Logging by patching the EventWrite function in ntdll.dll. allowing malicious activity to go unlogged; it doesn’t seem common.

Fig.5 disable windows event logging

 

And the second thing is to read the embedded malicious code from the batch file and to decode it, combining both Base64 and AES algorithms, and finally decompressing it and then executing it in memory. It is worth saying that it loads and executes a malicious .NET assembly in memory with System.Reflection.Assembly and Reverses the string "daoL" → "Load" (used to evade detection), finally connecting back to the attacker’s Command & Control (C2) server. The combining algorithm and compression are to avoid static detection, and it avoids file drops (fileless). All the above things are for evasion techniques.

Fig.6 base64, AES and compression to evasion detection

 

And the embedded malicious code mentioned above is the XClient v1.0.0.8 of the XWorm v5.6, with some related strings and the attacker’s IP address found in memory, and some other variable names were obfuscated.

Fig.7 XWorm and xclient


 Decompress file

to decompress the above-embedded malicious code, finding interesting strings to output the console: “Encerrado processo não elevado com PID, Erro ao tentar encerrar instâncias do BAT,” it seems that the language is Portuguese, specifically Brazilian Portuguese, based on the phrasing.

Fig.8 loader

 

Raw assembly file

To continue to track back to the raw assembly and dump to disk, the code without any obfuscation technique. And finally, it is sure XClient v.1.0.0.0 and XWorm 5.6. And after the deobfuscation technique, we have both files, which were uploaded to the bazaar.

Fig.9 XClient


Conclusion

From the above malware analysis, the attacker or threat actor combines script-based obfuscation (VBS/BAT/PS1) and multi-stages, which makes the process of attacking become more sophisticated, especially the key place uses the way of multi-algorithm like base64, AES, and compression to run in memory with fileless evasion detection. It indicates that the attack way that multi-stages and multi-algorithms in modern become more sophisticated and challenging. Let’s pay more attention to.

 

Diamond Model





MITRE ATT&CK TTP Mapping



IOCs

Files:

Sample md5 a2907290e94d10d566afaad71f0a77d2

Sample Sha256

ecb6c26329c5aa711c857bb37431b6d5037b0d28818af4c033c78231d007bb40

 

dwm.bat md5 da09177d362d929941b12939635446c3

dwm.bat sha256

c2b502c8dfa3d6ae57b9414fb537b63aea0de2f0f974225dd8280b2bfe8a8353


Decompress file:

Timestamp: 67D88CB4 (3/18/2025 4:57:24 AM)

Loader md5 ccc598563c870f9f47b8e367a025073a

Loader sha256
67a85b53d785054676f0db7f79fea437f7a87e1eeb4938c6efed2fc55a061359

 

Raw assembly file: Version XClient v1.0.0.0 XWorm V5.6

Timestamp: 67C14151 (2/28/2025 12:53:37 PM)
Raw assembly md5 6c0cdb74b4d168c964752ab7d363a99d
Raw assembly sha256
9fe006744c553edce0a1a28784b3598d41c53968502ba8c6454757e7eec83e40

 

Network:

Ip:45[.]138[.]16[.]211

Port: 7000

 

Files created:

C:\Users\<USER>\AppData\Local\Temp\WordDoc.bat

C:\Users\<USER>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\StartupScript_<randomstrings>.cmd

 

Files copied

C:\Users\<USER>\dwm.bat

 

Persistence

C:\Users\<USER>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\StartupScript_<randomstrings>.cmd

 

AES Algorithm in PS1:

Key: ozKAhHJS1dkh9XIxZ26zJxxrSxu58yYL8PIPHb6z5Gm (base64)

IV: qv7HfqoORsuVik33JVQxrg== (base64)

 

AES Algorithm in .Net loader:

Key: 8Bf7IumQkEqU854KLww9ILtzdkXFS4Anqt9sJFuAEoM= (base64)

IV: ypwf7u0VGAyrtOpzuHeBsA== (base64)

 

Key strings in Memory:
XWorm V5.6

XClient.exe

End.


──────────────────────
Seeker(李标明) · @clibm079    
China · Independent Malware Analyst & Researcher 


Labels: , , , , , ,

Thursday, March 20, 2025

The Art of Evasion: How Attackers Use VBScript and PowerShell in the Obfuscation Game

 


Summary

 

As we know, using obfuscated VBScript to execute obfuscated PowerShell is a common technique in malware to evade detection and complicate analysis. This approach leverages the strengths of both scripting languages while making it harder for security tools and analysts to understand the malicious intent.

 

Recently I came across a malware that is very well-designed for these obfuscation techniques to use, which is so interesting and attracted my curiosity to learn more about what’s happened inside the malware, and it was also low detection rate until first discovered.

 

Below, I would like to share how the attackers use VBScript and PowerShell to evade detection, maybe it can help other malware researchers or analysts, and the common technique but new doing uncommon which being talked on both VBScript obfuscation and PowerShell obfuscation.

 

 

Technical analysis

 

Basic info

The sample hashs:

md5 0e513e80fc18e3db4f0eb6ecb558534b

Sha256
7444d08579781b3d7b233e9fd3e7f9b31a85837c29adf2f4ae7965a628078639

 

 

VBScript obfuscation and evasion technique

In order to execute the VBScript, the attacker uses a mix of obfuscation that combines irrelevant comments, time-based delay, string splitting and concatenation, and dynamic behavior. It is very thoughtful. In addition, the structure of the VBScript code seems to intentionally disrupt logical order to interfere with analysts.

 

 

Adding Irrelevant Comments

The first sight is that the malware was inserted by a large number of difficult-to-understand comments or annotations, which seem like the stream of consciousness in monologues or novels or random text; its aim is to have a mind to interfere with or confuse or mislead information with analysts and antivirus.

Fig.1 a large number of understandable annotations for interfering

 

Ok, in order to do an analysis for this kind of malware, it is a time-consuming thing to remove all the annotations manually. The first thought is to use regular expression; a text editor like Sublime can help us to handle them. To replace all the single-line comment content with regular expressions is '.*$, but it should be done carefully because the obfuscation PowerShell will be replaced and should be checked later one by one.

Fig.2 regular expressions

 

 

Time-Based Obfuscation

Using time delays or conditions to execute parts of the script only after a certain time. Malware often uses time delays to evade sandbox detection and avoid immediate detection. Here, the VBScript code snippet appears to be a time-delay loop, starting a loop that continues until the current time Now() exceeds Suspensorium (i.e., for 9 seconds), and then it will loop 50 times and pause the script for 100 milliseconds (0.1 seconds) during each iteration of the loop, and the real PowerShell scripts will be executed when it Suspensorium exceeds 50.

Fig.3 VBScript Time delay to execute PowerShell

 

Combining obfuscation technique

The below VBScript code snippet demonstrates a malware evasion technique that combines time-based delays, string obfuscation, and dynamic behavior.

1.       String Obfuscation: pronegotiation= array(79+1,79,87,69,82,83,72,69,76,76), The array contains ASCII codes for the characters in the string "POWERSHELL"

2.       Time-Based Evasion: Checks if the current time (Now()) is less than the value of Suspensorium

3.       Dynamic Behavior: The script behaves differently depending on the current time

Fig.4 combining obfuscation technique

 

String splitting and Concatenation

 using ChrW(34) to concatenate strings that include double quotes, and using Chr(99) instead of the literal character 'c' makes the script harder to read and analyze; the command executes splitting to “Exe + chr(99) + “ute.”

Fig.5 VBScript String splitting and Concatenation

 

 

 

PowerShell obfuscation and evasion technique

In order to execute the PowerShell in VBScript, the attacker uses a user-defined algorithm and heavily obfuscates strings. It is different from other APT groups that use mature algorithms for obfuscation of strings; the attacker is very professional.

 

String splitting and Concatenation

The PowerShell code, the string splitting by well design in VBScript, and using the variable Hennafarvedes and character “&” for concatenation. And the variable in VBScript becomes a bridge in PowerShell scripts.

Fig.6 PowerShell String splitting and Concatenation

 

 

Specific Algorithm for Deobfuscated Script

The real intents in the well design strings, it extracts the characters by a specific algorithm with hardcode value: It iterates over the array, starting at index 4 and incrementing by 5 each time. The function returns the concatenated string.

Fig.7 specific algorithm for deobfuscated script

 

 

String obfuscation with inserting invalid characters

The below strings obfuscation technique is also very special; the valid characters are only used as a small part of them and used by a user-defined algorithm to extract them, but the unused strings are like random characters to insert and confuse analysts, like pouring a pile of garbage into a real PowerShell to conceal the attacker's intentions. From the above specific algorithm and hardcoded value, we can get a glimpse of being proficient in the use of obfuscation techniques by the attackers.

Fig.8 strings obfuscation


The real intent
From the above analysis, do further research analysis; the PowerShell script can download the payload from the remote URL address hxxps[:]//aghayezayeat.ir/kids/tyrosines.lzh and finally execute the payload. Here it is not special, and the URL can’t be accessed until now.

Fig.9 PowerShell snippet

 

 

Conclusion

From the above process of analysis, it shows that the attacker is very professional on combining different type of obfuscation techniques to do evasion and being proficient in programming, the malware sample tells cybersecurity community, the attacker always look for breakthroughs in defense and are very proactive, a more hidden threat around the digital world; let’s pay close attention.

 

 

IOCs

Files:

SKMBT20783_ZM.vbs md5 0e513e80fc18e3db4f0eb6ecb558534b

Sha256
7444d08579781b3d7b233e9fd3e7f9b31a85837c29adf2f4ae7965a628078639

 

Network:

hxxps[:]//aghayezayeat[.]ir/kids/Tyrosines.lzh

hxxps://aghayezayeat[.]ir/529/eiRBgmsetYWnjJJIug45[.]bin ( from vmray Platform)

185[.]159.153.133

 

Host:

C:\Users\kEecfMwgj\AppData\Roaming\Hikes.Ove

End.


──────────────────────
Seeker(李标明) · @clibm079    
China · Independent Malware Analyst & Researcher 

Labels: , , , , ,

Monday, March 10, 2025

Unmasking the Threat: Understanding Sophisticated Trojan-Dropper Mechanisms

 


Summary

 

First thanks for Szabolcs Schmidt was calling global malware analysts to analysis the samples on X, I’m really appreciate his work and he is helping to make cybersecurity more safer and stronger, I have no other words, you are doing an amazing work.

Abuse.ch's Malware Bazaar is an excellent platform for sharing and analyzing malware samples. By contributing to the community, I’m helping to improve global cybersecurity defenses and I’ve uploaded the
sample to share.

 

In this report, I do not plan to dive deep into all the details of the technique, but it is possible to make it up when having enough time to analyze; I would like to do that. In fact, it will learn more when diving deeper into the malware itself.

 

 

Technical analysis

 

Basic info

 

The sample hashs:

md5 A699AFD908E0DEC5C96FF7188450B89F

Sha256
f18631344d6f7fc57fd248edce37baeb11976e315b72b68d48311c406ace3f8c

 

Operation system: Operation system: Windows(95)[I386, 32-bit, GUI]

(Heur)Packer: Packer detected[High entropy + Section 1 (".data") compressed]

 

 

To observe the timeline and activities of the malware running in the sandbox, which created many files, such as DLLs and XML files, which created a task and connected to C2, from their behavior being checked, it is highly confident the malware is the type of Trojan dropper. After all, a logic flow graphic is as follows.

Fig.1 Trojan-Dropper Mechanisms

 

In the first stage, the Trojan dropper constantly tries to escalate privileges to execute malicious actions with the “runas” command in Windows, triggering a UAC prompt with a program name like “%sVerify-%s.exe,” which is created on the temp path like “C:\\Users\\XXX\\AppData\\Local\\Temp\\Verify-VBmJOhWZBbsNCmG.exe,” and once it is allowed to execute, it will drop a DLL file (e.g., eHMuMPu.dll). The eHMuMPu.dll will create a new XML file (e.g., dAdyJ6J.xml) and create the Trojan dropper itself with a new name (e.g., HfNUDO.exe) in the path like “C:\Program Files (x86)\Common Files\SpeechEngines\CSXW942RQP4MrCBvYGRyLsGsK\HfNUDO.exe.”. On the next step, it will continue to use the command line “schtasks /create /tn qb8iA2pa3SXfu /XML %AllUsersProfile%\Start Menu\6MGmiTas9Ndu41eCYbw\dAdyJ6J.xml /F” to create a new task named qb8iA2pa3SXfu with XML, which will execute the task every five minutes.

Fig.2 the first stage

 

In the second stage, the Trojan dropper HfNUDO.exe creates the DLL XSei1gC.dll on the “%AppData%\Media Center Programs\5xHEBJtPlIJ2Ifh\XSei1gC.dll”, and runs it with rundll32.dll in cmd.exe, which can query the details of the task qb8iA2pa3SXfu and create a new DLL BJtPlI.dll on the “%ProgramFiles% (x86)\Common Files\WanNengSoftManager\hI5sEDIwfuuZzva7AiY5A75x\BJtPlI.dll”. Because the Trojan dropper executes the task to do persistence every five minutes, which will create the two DLLs; they have the same abilities but different file names, so the DLLs can be observed in different directories. It is so crazy!

Fig.3 create DLLs with persistence task

 

When the BJtPlI.dll is created by XSei1gC.dll, it will go to the third stage, which will do antivirus and remove the Windows Defender as follows.

Fig.4 Anti Windows Defender

 

In the fourth stage, BJtPlI.dll will connect to the C2 server and execute the attacking campaign.

Fig.5 connect to C2 server

 

The C2 server can be accessed until the write-up is finished. Hunting down the IP 188[.]166.28.204, we can collect many attacking samples deployed by the threat actor. It seems that very hot attacking activities, maybe that’s why Szabolcs Schmidt was calling malware analysts, I’m really appreciate it again and I now do not dive deeper into the sample.

Fig.6 C2 server still working and hot attacking activities


Conclusion

From the above analysis, it appears that the malware is the type of Trojan dropper. It is a little bit new to use XML to create a task as a technique, and with multi-stage DLL techniques, it is highly confident that it is a skilled and experienced APT group, a more hidden threat around the digital world; let’s pay close attention.

 

 

IoCs

Files:

Trojan-Dropper Md5 A699AFD908E0DEC5C96FF7188450B89F

Sha256
f18631344d6f7fc57fd248edce37baeb11976e315b72b68d48311c406ace3f8c

 

Dropped by Trojan-Dropper:

dAdyJ6J.Xml md5 621d17a2e9562fb63248edec813fd481

Sha256

1853cc36050f36dc525ab479c77846e976525269066a6cf4bacc4e25eb55d465

 

eHMuMPu.dll md5 3c46ae847e57438d551ad2e5dceaa100

Sha256

107deecec00a31402430a813be00534e4a3cfc4ac5ded872caf4d2c50d117c25

 

BJtPlI.dll md5 056f31e74efa70a140105fdd74cff033

Sha256

6a66672beba2df1babb7801f63f3e171cf09b0807e1f7be86b42617a29eb983b

 

XSei1gC.dll md5 7c88d53706449de3a09dfd1ca60e81cb

Sha256

80c7d43c40872ff4b3a88f6d1dfe57c9facf9544eedfe08e7db7057e953eec9d

 

 

 

Host:

HKCU\Software\Microsoft\CTF\TOZYHhZP7JrXsnrqoh9bsgGED9aA

\SOFTWARE\Conexant\SAII\Controllayer\Si5cETIwNH7RbB7KQWrrV

cmd.exe /c rundll32 %ProgramFiles% (x86)\Common Files\SpeechEngines\GRyLsGsKSP7YyVjekJtym08\eHMuMPu.dll,

A31RU8dofhmCksIVB0GquGp0C8FYekLqp2qvDoSbkisXSjuqUyxv6KG2aaSOGLRUN

schtasks /query /tn qb8iA2pa3SXfu

schtasks /create /tn qb8iA2pa3SXfu /XML %AllUsersProfile%\Start Menu

\6MGmiTas9Ndu41eCYbw\dAdyJ6J.xml /F

%ProgramFiles% (x86)\Common Files\SpeechEngines\CSXW942RQP4MrCBvYGRyLsGsK\HfNUDO.exe

cmd.exe /c rundll32 %AppData%\Media Center Programs\5xHEBJtPlIJ2Ifh\XSei1gC.dll,

A31RU8dofhmCksIVB0GquGp0C8FYekLqp2qvDoSbkisXSjuqUyxv6KG2aaSOGLRUN

rundll32  %AppData%\Media Center Programs\5xHEBJtPlIJ2Ifh\XSei1gC.dll,

A31RU8dofhmCksIVB0GquGp0C8FYekLqp2qvDoSbkisXSjuqUyxv6KG2aaSOGLRUN

schtasks /query /tn qb8iA2pa3SXfu

schtasks /query /tn qb8iA2pa3SXfu /FO LIST /V

HKCU\Software\Microsoft\CTF\TOZYHhZP7JrXsnrqoh9bsgGED9aA

HKCU\Software\Microsoft\Sensors\aFIYzgtmOjU2vEv\XJkYu2C7y3NPUVxpnW5WxGs0ISC

rundll32 %ProgramFiles% (x86)\Common Files\WanNengSoftManager\hI5sEDIwfuuZzva7AiY5A75x\BJtPlI.dll,cmlPc6dI8

cmd.exe /c rd /q /s %ProgramFiles%\Windows Defender

cmd.exe /c rd /q /s %ProgramFiles% (x86)\Windows Defender

cmd.exe /c rd /q /s %AllUsersProfile%\Microsoft\Windows Defender

cmd.exe /c rd /q /s %ProgramFiles%\Windows Defender Advanced Threat Protection

cmd.exe /c rd /q /s %ProgramFiles% (x86)\Windows Defender Advanced Threat Protection

cmd.exe /c del %WinDir%\System32\MRT.exe /q /s /f

cmd.exe /c del %WinDir%\SysWOW64\MRT.exe /q /s /f

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA

HKLM\SOFTWARE\Policies\Microsoft\Microsoft Antimalware\DisableAntiVirus

HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\DisableAntiSpyware

HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\DisableRoutinelyTakingAction

HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\ServiceKeepAlive

HKCU\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks

\{C8E6F269-B90A-4053-A3BE-499AFCEC98C4}.check.0\CheckSetting

HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\DisableSpecialRunningModes

HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\DisableAntiVirus

HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\DisableRealtimeMonitoring

HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Signature Updates\ForceUpdateFromMU

HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet\DisableBlockAtFirstSeen

HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Features\TamperProtection

HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Windows Defender Antivirus\Cloud Delivered Protection\DisableCloudProtection

HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection\DisableRealtimeMonitoring

HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection\DisableBehaviorMonitoring

HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection\DisableScanOnRealtimeEnable

HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection\DisableOnAccessProtection

HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection\DisableIOAVProtection

HKLM\SOFTWARE\Policies\Microsoft\Windows\System\EnableSmartScreen

%ProgramFiles% (x86)\Common Files\SpeechEngines\GRyLsGsKSP7YyVjekJtym08\eHMuMPu.dll

%ProgramFiles% (x86)\Common Files\SpeechEngines\CSXW942RQP4MrCBvYGRyLsGsK\HfNUDO.exe

%AllUsersProfile%\Microsoft\Windows\Start Menu\6MGmiTas9Ndu41eCYbw\dAdyJ6J.xml

%ProgramFiles% (x86)\Common Files\WanNengSoftManager\hI5sEDIwfuuZzva7AiY5A75x\BJtPlI.dll

 

Network:

TCP 188[.]166.28.204:80

UDP 188[.]166.28.204:137 

End.


──────────────────────
Seeker(李标明) · @clibm079    
China · Independent Malware Analyst & Researcher 

Labels: , , , , ,