PULSE NAME
Plurox: Modular backdoor
WHITE AlienVault 2019-06-18 Modified: 2019-06-18
18
IOCs
MEDIUM VOLUME
In February this year, a curious backdoor passed across our virtual desk. The analysis showed the malware to have a few quite unpleasant features. It can spread itself over a local network via an exploit, provide access to the attacked network, and install miners and other malicious software on victim computers. What’s more, the backdoor is modular, which means that its functionality can be expanded with the aid of plugins, as required. Post-analysis, the malware was named Backdoor.Win32.Plurox.
Indicators of Compromise (15 / 18 total)
All URL domain hostname FileHash-MD5
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 a24fd434ffc7d3157272189753118fbf 2019-06-18
FileHash-MD5 b2d76d715a81862db84f216112fb6930 2019-06-18
FileHash-MD5 cd68adc0fbd78117521b7995570333b2 2019-06-18
FileHash-MD5 cecfd6bcfdd56b5cc1c129740ea2c524 2019-06-18
FileHash-MD5 b2824d2007c5a1077856ae6d8192f523 2019-06-18
FileHash-MD5 2e55ae88c67b1d871049af022cc22aac 2019-06-18
FileHash-MD5 8cf5c72217c1bb48902da2c83c9ccd4e 2019-06-18
FileHash-MD5 59523dd8f5ce128b68ea44ed2edd5fca 2019-06-18
FileHash-MD5 f233dd609821c896a4cb342cf0afe7b2 2019-06-18
FileHash-MD5 c4a74d79030336a0c3cf60de2cfae9e9 2019-06-18
FileHash-MD5 6915dd5186c65891503f90e91d8716c6 2019-06-18
FileHash-MD5 be591aa0e48e496b781004d0e833e261 2019-06-18
FileHash-MD5 e8aed94c43c8c6f8218e0f2e9b57f083 2019-06-18
FileHash-MD5 768857d6792ee7be1e1c5b60636501e5 2019-06-18
FileHash-MD5 117f978f07a658bce0b5751617e9d465 2019-06-18