MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 690c488a9902978f2ef05aa23d21f4fa30a52dd9d11191f9b49667cd08618d87. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



PlugX


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 690c488a9902978f2ef05aa23d21f4fa30a52dd9d11191f9b49667cd08618d87
SHA3-384 hash: 36f0368c89b339c9b37ea644bd688729f2add0d7f2d33623de3c1d837ef1e9cd748d811a51fc79fa74a8af796be15db6
SHA1 hash: 9be6a2bc9df78f4566e5690e2f1bb696ae96cb48
MD5 hash: 1ca0fbd832f9f7cdc0e50b29bd0d970f
humanhash: ceiling-don-sixteen-venus
File name:690c488a9902978f2ef05aa23d21f4fa30a52dd9d11191f9b49667cd08618d87.bin
Download: download sample
Signature PlugX
File size:35'328 bytes
First seen:2021-07-27 22:10:56 UTC
Last seen:2021-07-27 22:52:57 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 44cabbf1889efbd6905efce6c276dac1 (1 x PlugX)
ssdeep 768:GvenXjdk1B2hdbS4j5GC/yw1ghCtmnTEDkvvyowV:O1Aht8w1oCmmoM
TLSH T1CDF22811B2E5C576E27A653414B483720E6B3C316BF9408B7F9E16BA5FB12C0EA38357
Reporter Arkbird_SOLG
Tags:apt dll Plugx Thor Variant

Intelligence


File Origin
# of uploads :
2
# of downloads :
177
Origin country :
n/a
Vendor Threat Intelligence
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 455197 Sample: NYtweZzVyX.bin Startdate: 28/07/2021 Architecture: WINDOWS Score: 48 17 Multi AV Scanner detection for submitted file 2->17 7 loaddll32.exe 1 2->7         started        process3 process4 9 cmd.exe 1 7->9         started        11 rundll32.exe 7->11         started        13 rundll32.exe 7->13         started        process5 15 rundll32.exe 9->15         started       
Gathering data
Threat name:
Win32.Trojan.Plugx
Status:
Malicious
First seen:
2020-08-05 00:48:44 UTC
AV detection:
18 of 29 (62.07%)
Threat level:
  5/5
Verdict:
unknown
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Unpacked files
SH256 hash:
690c488a9902978f2ef05aa23d21f4fa30a52dd9d11191f9b49667cd08618d87
MD5 hash:
1ca0fbd832f9f7cdc0e50b29bd0d970f
SHA1 hash:
9be6a2bc9df78f4566e5690e2f1bb696ae96cb48
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments