
Purchase-Order VBS Downloader Now Delivers XWorm, Not Formbook
A CSV-spoofed VBS script tied to a familiar Spanish-language purchase-order lure now sandboxes to the XWorm remote-access trojan with a unanimous 3/3 malicious verdict, replacing the Formbook loader seen in prior tracking of the same delivery chain. The lure, file naming, and staging domain remain unchanged, pointing to a modular, payload-agnostic distribution pipeline.
A Payload Swap Behind a Familiar Purchase-Order Lure
A VBS script disguised with a CSV file signature — the same purchase-order-themed downloader CTX Team tracked in earlier coverage of this delivery chain — now sandboxes to a different terminal payload entirely. Where the prior reporting on this lineage centered on a Formbook loader, the newly submitted sample returns a 3/3 malicious consensus across CAPE Sandbox, Zenbox, and Yomi Hunter, with the sandbox layer explicitly naming the deployed family as XWorm, a commodity remote-access trojan. The lure hasn't changed. The file naming, the missing code-signing certificate, and the throwaway web infrastructure behind it haven't changed either. What has changed is the cargo — and on an otherwise stable delivery chain, that swap is the news.
Much of the campaign's observable toolset has turned over since that earlier reporting: the file set analyzed in this pass replaces the previously tracked samples wholesale, even as the lure template and staging domain remain fixed points across both windows. Files rotating while infrastructure and social-engineering material hold steady is a signature of a delivery pipeline that treats the final payload as an interchangeable component rather than a fixed design decision — closer to an affiliate drop service than a single actor's bespoke toolkit.
From Archive to Script: A Two-Stage, Low-Footprint Delivery Chain
The chain opens with a Spanish-language purchase-order lure: a 3KB RAR archive named "Orden de compra POF0000095-1.rar" [T1566.001], first submitted 2026-06-16. Static engines flag it at 14/76 — ALYac, Arcabit, BitDefender, DrWeb, ESET-NOD32, Kaspersky, and Microsoft among the fourteen that catch it — but sandboxing returns just 0/1 malicious, a profile consistent with a container waiting to be extracted rather than a file that executes on its own. Twenty of the engines that checked it, including several consumer AV suites, returned no verdict at all, underscoring how little behavioural signal a bare archive gives away before extraction.
The real execution stage sits inside: a script carrying the alternate names "Quotation.vbs" and "Orden de compra POF0000095.vbs," submitted a day later on 2026-06-17 and resubmitted through 2026-06-19. It's tagged "macro-powershell" and "calls-wmi," consistent with VBScript invoking Windows Management Instrumentation and PowerShell-style routines to interrogate and manipulate the host [T1059.005]. Detection sits at 22/75, with ALYac, AVG, Antiy-AVL, Arcabit, Avast, BitDefender, Google, Kaspersky, Microsoft, and Symantec among the flaggers — but notably, APEX, Acronis, AhnLab-V3, CrowdStrike, ESET-NOD32, and F-Secure all return no verdict, a gap that matters more than the raw ratio suggests given the sandbox-side confidence. All three sandboxes that processed the file agree it's malicious: CAPE Sandbox and Yomi Hunter both classify it outright as malware and name the family XWorm, while Zenbox adds a 76%-confidence verdict tagging the sample "SPREADER" and "EVADER" on top of the malware classification. Behavioural tags "idle" and "long-sleeps" point toward a deliberate execution-stalling routine — a pattern consistent with the script pausing to outlast the runtime window of automated sandboxes before proceeding to network activity [T1497.003], though this evasion mechanism is inferred from tagging rather than directly observed in a sleep-duration trace.
Three IDS rules fire on the same sample, and they tell an odd, only partly resolved story. "ET EXPLOIT_KIT Unknown EK Landing Feb 16 2015 b64 2 M1" and "ET DROP Spamhaus DROP Listed Traffic Inbound group 7" sit alongside "ET INFO KeyAuth Open-source Authentication System Domain in DNS Lookup (keyauth.win)" — the last of which suggests the script may resolve or reference KeyAuth, an open-source licensing and authentication service some malware operators repurpose to gate access to their builds. That's a low-confidence read: the rule fires on a DNS lookup, not a confirmed control relationship, but it's a thread worth flagging rather than dismissing. Twenty-three Sigma detections layer on top of the IDS hits, split across the Joe Security and Sigma Integrated rule sets and skewing toward medium and high severity — a dense rule-match footprint for a script that VirusTotal's static engines alone rate at less than a third detection.
A Same-Day Registration-to-Certificate Turnaround at basefile.click
The only network indicator in this snapshot is basefile.click, registered through Spaceship, Inc. on 2026-06-09. The same calendar day, the domain was issued a Let's Encrypt certificate (issuer CN "YR2") carrying a wildcard subject alternative name, *.basefile.click, valid from 2026-06-09 09:28:24 through 2026-09-07 09:28:23 — an 89-day validity window that's short even by Let's Encrypt's already-brief default terms, and a same-day domain-to-cert turnaround that reads as standard tradecraft for infrastructure meant to be used and discarded rather than maintained. The domain resolves to a single A record, 45.136.5.4, behind name servers ns1.whitelabelservices.us and ns2.whitelabelservices.us, and it hosts a resource named "optimized_MSIljune.png" — a filename that claims to be an image but sits on infrastructure otherwise built around a malware delivery chain, the kind of extension mismatch consistent with a staged payload retrieval point rather than genuine image hosting, though the article's evidence for that specific role is timing-based rather than a captured fetch.
That timing is worth sitting with: basefile.click's registration and certificate issuance land roughly a week ahead of the VBS downloader's first submission on 2026-06-17, a sequencing that fits a staging domain stood up just ahead of a distribution push. But the registrar itself, Spaceship, Inc., doesn't recur anywhere else in this indicator set, and no cert serial, name-server, or registrar axis ties basefile.click to any other tracked infrastructure. The domain's link to the file cluster rests entirely on that timing overlap and the shared campaign window — not on a cryptographic fingerprint or a hosting cohort that would let defenders pivot from one indicator to a wider fabric.
Build-Level Blind Spots and a Sharp Detection Asymmetry
Neither file in this snapshot carries an imphash or code-signing metadata, closing off the build-pipeline clustering that normally lets analysts tie a downloader lineage together across samples. Both the RAR carrier and the VBS payload sit isolated in the indicator set, with no shared imphash, signer, or threat label linking them at the build level. And yet the two share something else entirely: near-identical purchase-order lure naming — "Orden de compra POF0000095-1.rar" wrapping a script that itself carries the alternate name "Orden de compra POF0000095.vbs." That's a shared social-engineering template stamped across two files with no shared toolchain fingerprint, which is itself informative: it suggests a lure-generation step decoupled from whatever builds the payload, a division of labor typical of distribution-as-a-service setups rather than a single author hand-crafting each stage.
The detection numbers between the two stages diverge sharply enough to be a signal in their own right. The RAR carrier draws 14/76 with a 0/1 sandbox-malicious read; the VBS payload it likely delivers draws 22/75 but with a unanimous 3/3 malicious sandbox consensus, a named family classification, three IDS hits, and 23 Sigma matches. That's a textbook low-visibility wrapper sitting in front of a well-corroborated implant — the container that most engines wave through, hiding the script that every sandbox that touched it flagged outright.
A Broad, Industry-Agnostic Blast Radius
The targeting footprint behind this activity spans commercial services, education and research, government, manufacturing, legal offices, retail, support services, technology, telecom, and utilities, across a geographic spread that runs from Austria, Germany, France, the United Kingdom, Italy, and Poland through Australia, Canada, the United States, Mexico, India, Turkey, South Africa, and beyond. That kind of cross-sector, cross-region distribution — ten unrelated industries and roughly two dozen countries touched by the same lure template — reads as opportunistic business-correspondence spam rather than a deliberately selected target list; nothing in the sector mix suggests reconnaissance-driven targeting of a specific vertical.
No named actor or malware family is attributed to this activity by the upstream feed, and the evidence available doesn't support pinning one on. The broad, industry-agnostic targeting paired with a swappable commodity RAT payload is more consistent with financially motivated cybercrime — monetizing widescale remote access rather than pursuing a specific intelligence objective — but that read is an inference from targeting breadth and payload choice, not a confirmed attribution, and should be treated as low-confidence until firmer build-level or infrastructure fingerprints surface.
What the Payload Rotation Signals
Taken together, the pattern here is a delivery chain built around two durable components — a purchase-order lure template and a CSV-spoofed VBS downloader — wrapped around an interchangeable terminal payload. The same architecture that carried Formbook in earlier coverage now carries XWorm, with no visible change to the lure, the delivery mechanics, or the staging domain's registration pattern. That's consistent with a malware-distribution operation running on a modular, almost commoditized basis, where the downloader is the durable investment and the final-stage RAT is whatever's currently being pushed through the pipe.
It's worth being honest about how thin the underlying evidence base is for some of this: with only three tracked indicators, no shared imphash or signer axis between the two files, and no cross-IOC infrastructure cohort tying basefile.click to anything else in view, this assessment leans on naming overlaps and timing correlation rather than the cryptographic or hosting fingerprints that usually anchor a campaign-level claim. That's not a reason to discount the pattern — a downloader lineage surviving a full payload swap while its lure and infrastructure hold constant is itself a meaningful data point about how this operation is run — but it is a reason to treat the current picture as provisional. If a subsequent submission wave brings a shared imphash, a reused certificate, or a second domain tied to the same registrar pattern, the case for a persistent operator behind this lure template gets substantially stronger. Until then, what's confirmed is narrower but still notable: a stable social-engineering shell, indifferent to which commodity malware family rides inside it.