← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
IOC - From PyInstaller to XWorm V7.4: Infection Chain Analysis
Point Wild conducted an in-depth analysis of a suspicious PyInstaller-packed Python sample and identified it as a multi-stage malware loader designed to deploy the XWorm Remote Access Trojan (RAT), specifically associated with the XWorm V7.4 campaign. The sample leveraged multiple layers of obfuscation, staged execution and anti-analysis techniques to conceal its true functionality and evade detection by traditional security controls.
Indicators of Compromise (2 / 7 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA256 | 09c897832cc1b39c71da765f17adbe958551335f18d756905e733a05bfef697c | SHA256 of c7a6f220f2ff7d6718a5b2f0e85f13dd | 2026-05-22 | |
| FileHash-SHA256 | 9c30d62858fd5caf297cf503c63eea3b65325f74b972b2b7d523b7eb32c7656d | SHA256 of d4494a5b1430f7c5347408732cdbd668 | 2026-05-22 |