Malware Analysis - JS to PowerShell to XWorm with Binary Refinery

Опубликовано: 24 Март 2026
на канале: MalwareAnalysisForHedgehogs
2,418
78

We deobfuscate a JScript loader that downloads a powershell script, then we unpack the payload using Binary Refinery. We decrypt the configuration of the final payload: XWorm.

Malware analysis courses: https://malwareanalysis-for-hedgehogs...

XWorm config decrypter: https://github.com/struppigel/hedgeho...
Binary Refinery: https://github.com/binref/refinery
Sample: https://malshare.com/sample.php?actio...
atom.xml: https://malshare.com/sample.php?actio...

Buy me a coffee: https://ko-fi.com/struppigel
Follow me on Twitter:   / struppigel  

00:00 Intro
00:40 Triage on VirusTotal
02:24 Deobfuscation of JS
09:38 Obtaining atom.xml and triage
11:37 PowerShell decrypting the injector DLL
23:03 Injector DLL triage
24:55 Decrypting XWorm
28:08 XWorm triage, config location
30:12 Configuration decryption

#malware #xworm #javascript #malwareanalysis #rat #reverseengineering #js #jscript #powershell