MUSTANG_PANDA__2022__MustangPanda_-_Enemy_at_the_gate_final.pdf
ID: 11fe7a38-b7aa-4025-a9a7-184c4a688952
STIX ID: report--11fe7a38-b7aa-4025-a9a7-184c4a688952
Threat Score
85/100
Uploaded: 2026-08-19
Published Date: 2022-09-20
Last Modified Date: 2022-09-20
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report analyzes Mustang Panda (Chinese state-linked APT) campaigns that deployed PlugX/Hodur/THOR variants against Vietnamese and other regional targets. It contains static and dynamic analysis of loader DLLs (log.dll), encrypted payloads (log.dat), shellcode emulation and dumping, PlugX decompression and config decryption, C2s and configuration extraction, delivery via malicious LNKs and decoy documents, and several IOCs and sample hashes.
