IOC Radar
SHA256MediumSignal 95/100

e787f64af048b9cb8a153a0759555785c8fd3ee1e8efbca312a29f2acb1e4011

Location
PeruPeru
First Seen
Aug 27, 2025
Last Seen
Jul 20, 2026
Aug 27
First Seen
329d ago
Jul 20
Last Seen
yesterday
9
Reports
source reports
95%
Confidence
medium
Found in 9 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
SHA-256 Hash
SHA-256 file hash — primary identifier for malware samples.
MISP Category
Artifacts Dropped
Hash Algorithm
SHA256
Confidence
95%
Signal Score
95 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

71 techniques

Feed Intelligence Summary

9 reports95% confidence
9
Source reports
95%
Confidence score
Category tags
abuseactive scanactive scanningadversary-in-the-middleaitm attackaptauthentication attacksbackdoorbackdoor implantbad reputationblockbotnetbotnet activitybrute forcebrute force attackc2 communicationc2 ipc2 ip ioccaptive portalcaptive portal hijackcaptive portal hijackingcaptive portal redirectioncivil servicescommand & controlcommand and controlcompromise attemptcredential accesscredential stuffingcredential theftdata exfiltrationdata store exposuredigital signature abusedigital signaturesdigitally signeddiplomat targetingdistributed attacksdll side-loadingdll sideloadingespionage campaignexeexecutable fileexploitation activityfilefile-hashftp brute forceg0129government technologyhosting infrastructurehosting iphosting ip iochttps traffichttps traffic interceptionidentity & access exploitationidlein-memory executionindicatorinjection activityknbgxngds rc4landing pagelanding page iocloopmalmalicious softwaremalwaremalware deliverymalware infectionman-in-the-middleman-in-the-middle attackmemory injectionmessage queuemessage queuesmonitor yaramsi packagemsi package iocmsi payload deliverymsiemustang pandamutex namemutex name iocname iocnation-state activitynetwork intrusionnetwork scanningnexus espionageoperating systempage httpspassword attackspedllperuphishingplugxplugx malwareplugx variantprc-nexus aptprocess injectionpublic administrationpublic infrastructurepublic policyqueue windowsransomwarereconnaissanceregion: southeast asiaregulatory agenciesremote accessremote servicesresearchedrulessecurity operationsservice scansignedsigned malwaresocial engineeringsogu.secsouth americasoutheast asiaspearphishingssh attacksupply chain attacksyn scant1012t1016t1021t1021.001t1027t1033t1036t1041t1048t1055t1055.001t1057t1059t1059.001t1059.003t1069.001t1071t1071.001t1076t1078t1078.001t1078.003t1082t1083t1095t1105t1110t1110.001t1110.002t1110.003t1110.004t1113t1124t1132t1132.001t1133t1140t1189t1190t1195t1195.002t1199t1202t1204t1204.002t1218t1218.011t1486t1496t1497t1499.002t1499.003t1546t1553t1553.002t1556t1563t1565t1566t1566.001t1566.002t1574t1574.002t1583t1583.001t1588t1588.002t1595t1595.001t1595.002t1595.003threat actorthreat actor: unc6384threat intelligencetor nodetyposquattingudp port scanunc6384valid certificate abuseweb hijackingweb traffic hijackingweb traffic redirectionwin32 malwarewindowswindows malwarewindows messagewindows message queueswindows ntwindows systemwindows systems

Activity Timeline

1 total obs
Jul 20Jul 20

Threat Activity Heatmap

Less
More
Mon
Wed
Fri
Jul
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
·
·
Jul
·
24h
0
Dormant
7d
1
Minimal
30d
1
Minimal
3mo
1
Minimal
Intelligence SummaryAI Generated

The identified SHA-256 hash represents a high-severity threat indicator associated with sophisticated cyber-espionage activities. This artifact has been linked to the Mustang Panda advanced persistent threat (APT) group, an adversary known for targeting diplomatic entities and government organizations to facilitate intelligence gathering. The presence of this hash in an environment indicates a significant risk of system compromise, potentially facilitating long-term persistence and unauthorized …

Threat ScoreHigh Risk
95
SIGNAL
Signal Score
95%
Confidence
9
Reports
First seenAug 27, 2025
Last seenJul 20, 2026

VirusTotal

Not checked

WHOIS

description
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
references
https://cloud.google.com/blog/topics/threat-intelligence/prc-nexus-espionage-targets-diplomats, https://cloud.google.com/blog/topics/threat-intelligence/prc-nexus-espionage-targets-diplomats/

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 10 months ago · Last seen 1 day ago
Appeared in 9 threat reports