MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2f58a869711d2b28e6ecaac25cc2166daa46f7adfb719b7dd334e01c1474ca9b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



PlugX


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 2f58a869711d2b28e6ecaac25cc2166daa46f7adfb719b7dd334e01c1474ca9b
SHA3-384 hash: 75a1418b9f5fb52793b5034e65f9e72390d58cb87564adf78bd933ee81b1f0507053d4c6a9165a3099e03e91c2eddf10
SHA1 hash: 9fabc6c255ea94262b6339e4b5949174afd30114
MD5 hash: f782fa626b0c53d9cca2fbb29a65f23f
humanhash: tango-may-ten-colorado
File name:2f58a869711d2b28e6ecaac25cc2166daa46f7adfb719b7dd334e01c1474ca9b.dll
Download: download sample
Signature PlugX
File size:164'352 bytes
First seen:2021-08-06 12:17:25 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 397051b6d9c5c8b855041d0a2769af43 (2 x PlugX)
ssdeep 3072:SXZC1fhEIosP/HMP7kUj6IXE6i1xRqLCJVQPyR:uC1fWIpP/H67kU+I06i1DB
Threatray 3 similar samples on MalwareBazaar
TLSH T1CBF31800E040D3B6E4BA40F94BBDAE5B257DA962071515DF37C29C3E79D2DE16B38E22
Reporter Anonymous
Tags:decrypted dll Plugx

Intelligence


File Origin
# of uploads :
1
# of downloads :
205
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
clean
Classification:
n/a
Score:
7 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Win32.Trojan.Sabsik
Status:
Malicious
First seen:
2021-08-06 12:18:12 UTC
File Type:
PE (Dll)
Extracted files:
1
AV detection:
23 of 46 (50.00%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:plugx
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Malware Config
C2 Extraction:
103.192.226.100:80
103.192.226.100:110
103.192.226.100:8080
Unpacked files
SH256 hash:
2f58a869711d2b28e6ecaac25cc2166daa46f7adfb719b7dd334e01c1474ca9b
MD5 hash:
f782fa626b0c53d9cca2fbb29a65f23f
SHA1 hash:
9fabc6c255ea94262b6339e4b5949174afd30114
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments