RedDelta PlugX Undergoing Changes and Overlapping Again with Mustang Panda PlugX Infrastructure
Tags
country: | Hong Kong Mongolia Vietnam |
attack-pattern: | Domains - T1583.001 Domains - T1584.001 Malware - T1587.001 Malware - T1588.001 Python - T1059.006 |
Common Information
Type | Value |
---|---|
UUID | b20ce28e-3c46-4184-8a88-6c0add0a2ef9 |
Fingerprint | a53da9b86bbe849f |
Analysis status | DONE |
Considered CTI value | 2 |
Text language | |
Published | June 2, 2021, midnight |
Added to db | Sept. 26, 2022, 9:31 a.m. |
Last updated | Sept. 4, 2024, 6:28 p.m. |
Headline | Blog |
Title | RedDelta PlugX Undergoing Changes and Overlapping Again with Mustang Panda PlugX Infrastructure |
Detected Hints/Tags/Attributes | 36/2/17 |
Source URLs
Redirection | Url | |
---|---|---|
Details | Source | https://blog.xorhex.com/blog/reddeltaplugxchangeup/ |
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 1 | vitedannews.com |
|
Details | File | 1 | smaddb.dat |
|
Details | File | 12 | strings.exe |
|
Details | sha256 | 1 | 1c7897a902b35570a9620c64a2926cd5d594d4ff5a033e28a400981d14516600 |
|
Details | sha256 | 1 | ec1c29cb6674ffce989576c51413a6f9cbb4a8a41cbd30ec628182485a937160 |
|
Details | sha256 | 1 | dba437c9030b5f857ce9820a0c9e2c252fd8aeda71c2101024d3576c446972a0 |
|
Details | sha256 | 1 | a1eb4ce6eaa0c35ca4e8285c32b59cd0dfb34018b3f454d4fa4cebe9906534d8 |
|
Details | sha256 | 1 | 2304891f176a92c62f43d9fd30cae943f1521394dce792c6de0e097d10103d45 |
|
Details | sha256 | 1 | 2f58a869711d2b28e6ecaac25cc2166daa46f7adfb719b7dd334e01c1474ca9b |
|
Details | sha256 | 1 | 2bfd100498f70938dedef42116af09af2db77ef1315edcea0ffd62c93015ddf5 |
|
Details | sha256 | 1 | b87d1c01daee804c7330d5ac6273e5dcba886e1663c929709c158fd45b11a7ba |
|
Details | sha256 | 1 | 4e30cfa4f3d3bd6192818c5619eb7f6a26a408ae9fd62a7629059f47466f757b |
|
Details | sha256 | 1 | 2531af12360e29b73b545210e1cbdfc2459c95e2827d3246e9d6933820a808dd |
|
Details | sha256 | 1 | 4b1dbb3fc4adba3a83a563e5e86afb56136a1f9ba0293ad21a00e031b88b2ad9 |
|
Details | sha256 | 2 | f631e8f0c723cccbc5b26387f4100351de2e158b6770e962733734be6ca119d5 |
|
Details | sha256 | 1 | 76f44175f88984367ad62c81d1dcc947b1a26d6832fd33569d2c21113c1ddee2 |
|
Details | IPv4 | 4 | 101.36.125.203 |