PULSE NAME
PlugX targets Hong Kong
WHITE Mustang Panda AlienVault 2020-02-11 Modified: 2020-02-11
18
IOCs
MEDIUM VOLUME
MMustang Panda is a well-known APT with a long history of targeting non-governmental organisations (NGOs). It utilizes shared malware like Poison Ivy, PlugX and Cobalt Strike payloads in order to gather intelligence. Since 2008, PlugX as a RAT (Remote Access Trojan) malware family has been used as a backdoor to control the victim’s machine fully. Once the device is infected, an attacker can remotely execute several kinds of commands on the affected system to retrieve machine information, capture the screen, manage services, and manage processes.
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
PlugX Trojan:Win32/Korplug
Indicators of Compromise (10 / 18 total)
All FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 59aaa2b8116ba01c1b37937db37213ff1f4a8552a7211ab21f73ffac2c0c13ce 2020-02-11
FileHash-SHA256 918de40e8ba7e9c1ba555aa22c8acbfdf77f9c050d5ddcd7bd0e3221195c876f 2020-02-11
FileHash-SHA256 b9f3cf9d63d2e3ce1821f2e3eb5acd6e374ea801f9c212eebfa734bd649bec7a 2020-02-11
FileHash-SHA256 14f9278f3515fae71ccb8073cfaf73bdcc00eab3888d8cee6fb43a4f51c9e699 2020-02-11
FileHash-SHA256 c90cae0a4365cb31f171b051520f6c8053dd0c3e798c59b2ae418bf99ddad02c 2020-02-11
FileHash-SHA256 8be6c10e9e150d01601f77485444e409667ba905100982f57743e01d20a26121 2020-02-11
FileHash-SHA256 6b23a388ddb3b697004fdd37a0d393455ae5702040c2b694f9158112698c2ec1 2020-02-11
FileHash-SHA256 6fc8c2e28dfa39b20154ecb3339eb784a025ea1a7c79e15e0930f679280bb63e 2020-02-11
FileHash-SHA256 f331eb3d7f6789e48f2e3bfb1a87595561722f45aaec150df537488587024096 2020-02-11
FileHash-SHA256 6924581b5fee4699a1ce0182cdf8462d5fcb5389985ec129d554dd6ca45d0c9f 2020-02-11