XWorm Malware Delivered via Email Attachment Infects Windows Host, C2 to 43.228.157.141
What Happened – A malicious JavaScript file (identified as XWorm) was delivered in a password‑protected RAR archive attached to a phishing email. The payload established command‑and‑control communication with 43.228.157.141:7007 on a Windows workstation. The infection was short‑lived and did not survive a reboot, but the traffic demonstrates a successful initial compromise.
Why It Matters for Trust & Control Assurance
- This scenario tests the effectiveness of email‑gateway filtering and user‑awareness programs that a continuous control‑assurance regime must monitor and evidence.
- Detecting and logging C2 traffic provides the audit‑ready artifacts needed to prove that inbound/outbound network controls are operating as intended.
- Mapping the incident to the “email security and phishing resilience” control area shows how a single control objective supports multiple frameworks (e.g., NIST CSF Identify & Protect, ISO 27001 A.7).
Who Is Affected – Any organization that relies on email for business communications, across all industry sectors.
Recommended Actions
- Verify that email security gateways block password‑protected archives and unknown script types.
- Refresh Security Awareness Training with a focus on malicious attachment handling and phishing indicators.
- Enable continuous network monitoring for outbound connections to suspicious IPs and retain logs for audit purposes.
Source: Malware‑Traffic‑Analysis.net – XWorm infection (09/08/2026)
Technical Notes
- Delivery vector: phishing email with RAR‑packed LZH file.
- Payload: JavaScript (SHA‑256 5ba1eee1204710adfe1963b730de79c7a8089b173e811052e7be464fc5da1a1d).
- C2 endpoint: TCP 43.228.157.141:7007.
- No persistence; infection cleared after reboot.
Source: sandbox analyses – JoeSandbox, Tri‑age, Any.run