MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9699c3f5dd99345b04aaf5e7dc5002de7dbabf922e43125a10eb3f5fc574e51e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



PlugX


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 9699c3f5dd99345b04aaf5e7dc5002de7dbabf922e43125a10eb3f5fc574e51e
SHA3-384 hash: 020c2cb5770428e008275c62b9846772332b990d62e01e6b0afa224f342e1d1da362bdcebfd172d2045b77565f964ffb
SHA1 hash: e6801d03987e03a9dce1e7e149c770804d2cc4e8
MD5 hash: 3200aaf8794043c35f6b2145c6af1bf1
humanhash: batman-vermont-south-speaker
File name:9699c3f5dd99345b04aaf5e7dc5002de7dbabf922e43125a10eb3f5fc574e51e
Download: download sample
Signature PlugX
File size:8'617'438 bytes
First seen:2021-08-02 09:22:09 UTC
Last seen:2021-08-02 09:32:55 UTC
File type: rar
MIME type:application/x-rar
ssdeep 196608:UfD/h/Ynv00lfl8lR1zoH+sNhK24Lho7H849/YXHC1dpJ+9OB2IPDoP:EDhAvLfWlvKpNYO7f1YXHCbP72QMP
TLSH T186963362FD23A4ECF16C66334BC462762247B81476746DD2D239B53FF36918A4034BAE
Reporter JAMESWT_WT
Tags:Plugx rar

Intelligence


File Origin
# of uploads :
2
# of downloads :
165
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.DllHijack
Status:
Malicious
First seen:
2020-08-04 12:31:51 UTC
File Type:
Binary (Archive)
Extracted files:
713
AV detection:
25 of 46 (54.35%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
bootkit persistence
Behaviour
Modifies Internet Explorer settings
Suspicious use of SetWindowsHookEx
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments