<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>ThreatActor on Custom Tools, Reverse Engineering, and Threat Research</title><link>https://blog.xorhex.com/categories/threatactor/</link><description>Recent content in ThreatActor on Custom Tools, Reverse Engineering, and Threat Research</description><generator>Hugo -- gohugo.io</generator><language>en</language><lastBuildDate>Wed, 02 Jun 2021 00:00:00 +0000</lastBuildDate><atom:link href="https://blog.xorhex.com/categories/threatactor/index.xml" rel="self" type="application/rss+xml"/><item><title>RedDelta PlugX Undergoing Changes and Overlapping Again with Mustang Panda PlugX Infrastructure</title><link>https://blog.xorhex.com/blog/reddeltaplugxchangeup/</link><pubDate>Wed, 02 Jun 2021 00:00:00 +0000</pubDate><guid>https://blog.xorhex.com/blog/reddeltaplugxchangeup/</guid><description>&lt;table>
&lt;thead>
&lt;tr>
&lt;th>&lt;/th>
&lt;th>&lt;/th>
&lt;/tr>
&lt;/thead>
&lt;tbody>
&lt;tr>
&lt;td>Family&lt;/td>
&lt;td>PlugX - RedDelta Variant&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>Threat Actor&lt;/td>
&lt;td>Mustang Panda&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>Encrypted&lt;/td>
&lt;td>1c7897a902b35570a9620c64a2926cd5d594d4ff5a033e28a400981d14516600&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>Decryption Key&lt;/td>
&lt;td>0x78, 0x61, 0x6c, 0x72, 0x45, 0x5a, 0x6f, 0x78, 0x43, 0x59, 0x73, 0x71, 0x6c, 0x52, 0x6e, 0x77, 0x78, 0x46, 0x63, 0x43, 0x46&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>Key Length&lt;/td>
&lt;td>21&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>Decrypted&lt;/td>
&lt;td>ec1c29cb6674ffce989576c51413a6f9cbb4a8a41cbd30ec628182485a937160&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>Config C2&lt;/td>
&lt;td>101.36.125.203:965&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>Config C2&lt;/td>
&lt;td>101.36.125.203:110&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>Config C2&lt;/td>
&lt;td>vitedannews.com:965&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>Config C2&lt;/td>
&lt;td>vitedannews.com:110&lt;/td>
&lt;/tr>
&lt;/tbody>
&lt;/table></description></item><item><title>Mustang Panda PlugX - Reused Mutex and Folder Found in the Extracted Config</title><link>https://blog.xorhex.com/blog/mustangpandaplugx-2/</link><pubDate>Thu, 27 May 2021 00:00:00 +0000</pubDate><guid>https://blog.xorhex.com/blog/mustangpandaplugx-2/</guid><description>&lt;table>
&lt;thead>
&lt;tr>
&lt;th>&lt;/th>
&lt;th>&lt;/th>
&lt;/tr>
&lt;/thead>
&lt;tbody>
&lt;tr>
&lt;td>Family&lt;/td>
&lt;td>PlugX - Variant: &lt;code>XXXXXXXX&lt;/code> Config Check&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>Threat Actor&lt;/td>
&lt;td>Mustang Panda / Red Delta&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>Encrypted&lt;/td>
&lt;td>de0f65a421ce8ee4a927f4f9228f29ff12be69ac71edecb18c35cb5101e4c3cf&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>Decrypted&lt;/td>
&lt;td>2bfd100498f70938dedef42116af09af2db77ef1315edcea0ffd62c93015ddf5&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>XOR Decyption Key&lt;/td>
&lt;td>0x4b, 0x73, 0x51, 0x4f, 0x74, 0x6d, 0x49, 0x68, 0x63, 0x43&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>XOR Decryption Key Length&lt;/td>
&lt;td>10&lt;/td>
&lt;/tr>
&lt;/tbody>
&lt;/table></description></item><item><title>Mustang Panda PlugX - 45.251.240.55 Pivot</title><link>https://blog.xorhex.com/blog/mustangpandaplugx-1/</link><pubDate>Mon, 17 May 2021 00:00:00 +0000</pubDate><guid>https://blog.xorhex.com/blog/mustangpandaplugx-1/</guid><description>&lt;table>
&lt;thead>
&lt;tr>
&lt;th>&lt;/th>
&lt;th>&lt;/th>
&lt;/tr>
&lt;/thead>
&lt;tbody>
&lt;tr>
&lt;td>Family&lt;/td>
&lt;td>PlugX&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>Threat Actor&lt;/td>
&lt;td>Mustang Panda&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>Encrypted&lt;/td>
&lt;td>589e87d4ac0a2c350e98642ac53f4940fcfec38226c16509da21bb551a8f8a36&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>Decrypted&lt;/td>
&lt;td>dce920f5db90efecc7fb7a6b6399c80fc83e3f1251f160cd1295b6a4b67125d4&lt;/td>
&lt;/tr>
&lt;/tbody>
&lt;/table></description></item></channel></rss>