MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3a53bd36b24bc40bdce289d26f1b6965c0a5e71f26b05d19c7aa73d9e3cfa6ff. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



PlugX


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 3a53bd36b24bc40bdce289d26f1b6965c0a5e71f26b05d19c7aa73d9e3cfa6ff
SHA3-384 hash: cf51f69f81b03af4a228d984c218f0972c9a5f18f29507bbeae70fede72f4fb21127a44bf431f20d5dc4be68c6df59b6
SHA1 hash: ee4b5f18b4fad719764ac405a56c6dba90d0b554
MD5 hash: fc55344597d540453326d94eb673e750
humanhash: steak-butter-freddie-potato
File name:3a53bd36b24bc40bdce289d26f1b6965c0a5e71f26b05d19c7aa73d9e3cfa6ff
Download: download sample
Signature PlugX
File size:77'824 bytes
First seen:2021-08-02 09:20:34 UTC
Last seen:2026-03-13 18:45:45 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 0351c0e34f10f7c206f62b43a6a669a8 (1 x PlugX)
ssdeep 1536:JDkJ1hfUkwzooFc50+2Jzynhxot/ZQTZ6TCCBjmna7yt2:iTgeCP7yt2
Threatray 5 similar samples on MalwareBazaar
TLSH T136737D117691D9B2CC8E42795509CB12776A3231AEF9C8833F9B1B8D6F212D4AB3F345
Reporter JAMESWT_WT
Tags:dll Plugx

Intelligence


File Origin
# of uploads :
2
# of downloads :
168
Origin country :
US US
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
56 / 100
Signature
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 457840 Sample: O4xMF88Vea Startdate: 02/08/2021 Architecture: WINDOWS Score: 56 29 Antivirus / Scanner detection for submitted sample 2->29 31 Multi AV Scanner detection for submitted file 2->31 8 loaddll32.exe 1 2->8         started        process3 process4 10 cmd.exe 1 8->10         started        12 rundll32.exe 8->12         started        14 rundll32.exe 8->14         started        16 8 other processes 8->16 process5 18 rundll32.exe 10->18         started        20 WerFault.exe 2 9 12->20         started        22 WerFault.exe 9 14->22         started        process6 24 WerFault.exe 23 9 18->24         started        dnsIp7 27 192.168.2.1 unknown unknown 24->27
Threat name:
Win32.Trojan.Ymacco
Status:
Malicious
First seen:
2020-11-10 14:46:02 UTC
File Type:
PE (Dll)
AV detection:
28 of 46 (60.87%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Unpacked files
SH256 hash:
3a53bd36b24bc40bdce289d26f1b6965c0a5e71f26b05d19c7aa73d9e3cfa6ff
MD5 hash:
fc55344597d540453326d94eb673e750
SHA1 hash:
ee4b5f18b4fad719764ac405a56c6dba90d0b554
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments