Malware Signature

The following table shows a list of malware samples and the corresponding botnet C&C (ip:port) associated with XFilesStealer

Database Entry


Malware:XFilesStealer
First seen:2022-06-12 18:15:07 UTC
Last seen:2022-07-27 16:58:25 UTC

Malware Samples


The table below documents all malware samples associated with this malware family.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2022-07-27 16:58:25033e24f75513450128f833238b9365cbVirustotal results 35 / 71 (49.30%) XFilesStealer165.22.226.149:8008
2022-07-26 15:32:596469b2046d39cbb049465d0603651645n/aXFilesStealer62.108.37.84:8881
2022-07-25 11:16:082fc31fe50927c2855aa8dcd1f21b01eeVirustotal results 48 / 70 (68.57%) XFilesStealer193.149.3.239:1938
2022-07-18 18:42:32cb30e0b296fd0d35e3d6a9629e06a7b1Virustotal results 45 / 70 (64.29%) XFilesStealer3.64.4.198:13315
2022-07-07 01:40:579f7d48fd36a1493b4c25131f95339bd6Virustotal results 43 / 69 (62.32%) XFilesStealer3.67.15.169:12728
2022-07-04 20:16:185cfca76bbb5a47cca3d51add90966fcaVirustotal results 27 / 69 (39.13%) XFilesStealer51.116.125.149:3537
2022-06-12 18:15:071cd8a8c46a32757f9e5288ea943de6f3Virustotal results 38 / 53 (71.70%) XFilesStealer77.247.127.10:9898