4547914e17c127d9b53bbc9d44de0e5b867f1a86d2e5ede828cd3188ed7fe838
Classification: Malicious
4547914e17c127d9b53bbc9d44de0e5b867f1a86d2e5ede828cd3188ed7fe838 is a malicious file sample. Linked to Mustang Panda activity.
Detection summary
- 36 antivirus detections (51% detection ratio)
- 0 IDS alerts
- 7 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2023-07-04 19:45:03 |
2024-12-12 17:45:05 |
|
|
| Ta428 |
Maltiverse |
2023-07-04 04:29:44 |
2023-07-05 20:50:39 |
malicious-activity
|
|
| Generic.Malware |
Maltiverse |
2023-07-05 11:14:10 |
2023-07-05 11:14:10 |
|
G0129 Mustang Panda
|
Tags
apt
malware
backdoor
plugx
Sample information
- Filenames
- 4547914e17c127d9b53bbc9d44de0e5b867f1a86d2e5ede828cd3188ed7fe838
- File type
- PE32 executable (DLL) (GUI) Intel 80386, for MS Wi ...
- Size
- 77824 bytes
- MD5
b03636cdd9740c91b89ca50cda27da49
- SHA-1
426661c503c90655b001b1499a530f295f25551b
- SHA-256
4547914e17c127d9b53bbc9d44de0e5b867f1a86d2e5ede828cd3188ed7fe838
- First indexed
- 2023-07-04 19:21:53
- Last updated
- 2024-12-12 17:45:05
Antivirus detections
| Engine | Detection |
| Bkav | W32.AIDetectMalware |
| Lionic | Trojan.Win32.Generic.4!c |
| MicroWorld-eScan | Trojan.GenericKD.67413522 |
| FireEye | Trojan.GenericKD.67413522 |
| McAfee | Artemis!B03636CDD974 |
| Cylance | unsafe |
| Sangfor | Trojan.Win32.Agent.Vjoo |
| K7AntiVirus | Trojan ( 005940101 ) |
| K7GW | Trojan ( 005940101 ) |
| Cyren | W32/ABRisk.SXAW-5046 |
| Symantec | ML.Attribute.HighConfidence |
| ESET-NOD32 | a variant of Win32/Korplug.TX |
| APEX | Malicious |
| Cynet | Malicious (score: 100) |
| Kaspersky | Trojan.Win32.Dllhijacker.aex |
| BitDefender | Trojan.GenericKD.67413522 |
| Avast | Win32:MalwareX-gen [Trj] |
| Rising | [email protected] (RDML:vm91SuP3nuP/7ivsQQe8SQ) |
| Sophos | Mal/Generic-S |
| VIPRE | Trojan.GenericKD.67413522 |
| McAfee-GW-Edition | BehavesLike.Win32.BadFile.lh |
| Emsisoft | Trojan.GenericKD.67413522 (B) |
| GData | Trojan.GenericKD.67413522 |
| Webroot | W32.Trojan.GenKD |
| Antiy-AVL | Trojan/Win32.Korplug |
| Arcabit | Trojan.Generic.D404A612 |
| ZoneAlarm | Trojan.Win32.Dllhijacker.aex |
| Microsoft | Trojan:Win32/Casdet!rfn |
| Google | Detected |
| AhnLab-V3 | Trojan/Win.Generic.C5449325 |
| BitDefenderTheta | Gen:NN.ZedlaF.36270.eq4@aO0Pdoj |
| ALYac | Trojan.Korplug.A |
| MAX | malware (ai score=81) |
| TrendMicro-HouseCall | TROJ_GEN.R002H09F923 |
| AVG | Win32:MalwareX-gen [Trj] |
| DeepInstinct | MALICIOUS |
Process list
| Name | Command line |
| <Ignored Process> | |
| rundll32.exe | "C:\4547914e17c127d9b53bbc9d44de0e5b867f1a86d2e5ede828cd3188ed7fe838.dll",#1 /verbose |
| <Ignored Process> | |
| rundll32.exe | "C:\4547914e17c127d9b53bbc9d44de0e5b867f1a86d2e5ede828cd3188ed7fe838.dll",#1 |
| WerFault.exe | -u -p 2804 -s 652 |
| WerFault.exe | -u -p 2804 -s 652 |
| WerFault.exe | -u -p 2804 -s 652 |