Have you found a way to detect xworm c2c servers?
One path I looked at was to use the VirusTotal API to help identify C2's that other security organizations were identifying and leverage that to automatically take down malicious TCP endpoints. I wrote some POCs but did not deploy them. It's something I plan on taking up again at some point next year.
feel free to give me a ping on https://discord.gg/AXAbujx @patrick.