MALICIOUS — 3d6b24a04634f0f724a119d596491942f281f7fd4c36aea10daf427c91fb93fa.exe
MALICIOUS — 3d6b24a04634f0f724a119d596491942f281f7fd4c36aea10daf427c91fb93fa.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (91/100). 4 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
3d6b24a04634f0f724a119d596491942f281f7fd4c36aea10daf427c91fb93fa - SHA-1:
684e59d5a061f7804ebd2b581ac8c8123accca18 - MD5:
5ec223d30c5bd441ab6f5a703433ae6e - imphash:
42492c8bc2aad1800e134cedaf5754c9 - ssdeep:
98304:jhgtsTICDtPfeE/jowqK5LN1KQ0oTh2M9QrABlolllXHNAMZr6u8:AsTICteErownP0oTcMsABqljk/ - TLSH:
T19965331542023792EEF3E960EC809C4D8473B699A873D19C5987CD5E70E9D33A8F0B96 - Submitted as: 3d6b24a04634f0f724a119d596491942f281f7fd4c36aea10daf427c91fb93fa.exe
- File type: pe · Size: 5632992 bytes
- Verdict: malicious (91/100)
Source: MalwareBazaar · first seen 2026-08-01T00:00:00.000Z · SHA-256 verified
Detections (4 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): PyInstaller
- Detect It Easy (packer/type): DIE:PyInstaller
- Kaspersky (KVRT): Trojan-Dropper.Win32.Sysn.dnqr
- Emsisoft (Emergency Kit): Gen:Variant.Adware.Yogi.1551
MITRE ATT&CK
Why this verdict
The malicious score of 91/100 is the fusion of 7 weighted signals:
- Memory forensics: 3 finding(s), e.g. RWX/private injected region in powershell.exe (pid 1916) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - 1 behavioral detection(s): Possible DNS tunneling (long/many queries) [medium] (rule
tl-dns-tunneling) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 80 external host(s) at runtime (10 HTTP) - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1082, T1497 - dynamic signal, weight 0.40, confidence 0.75
- Detect It Easy (packer/type) flagged DIE:PyInstaller (rule
DIE:PyInstaller) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: PyInstaller - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
17204 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- d.1.d.1.c.4.2.1.4.9.5.2.6.e.8.b.0.0.0.0.0.0.0.0.0.0.0.0.0.8.e.f.ip6.arpa.
- 251.0.0.224.in-addr.arpa.
- 209.52.40.23.in-addr.arpa.
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- 252.0.0.224.in-addr.arpa.
- ifconfig.me
- tas02.sls.update.microsoft.com
- login.live.com
- ctldl.windowsupdate.com
- 164.142.190.20.in-addr.arpa.
- go-ns.org.ua
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- ocsp.digicert.com
- 170.85.21.104.in-addr.arpa.
- settings-win.data.microsoft.com
- ..localmachine
- DESKTOP-HSGCBEP
- v10.events.data.microsoft.com
- config.edge.skype.com
Embedded URLs
- http://schemas.microsoft.com/SMI/2016/WindowsSettings
Embedded domains
- schemas.microsoft.com
- 8.gq
- ifconfig.me
- go-ns.org.ua
- t.me
- www.tiktok.com
- ..localmachine
Embedded IP addresses
- 4.150.223.102
- 135.233.45.221
- 74.179.77.204
- 34.160.111.145
- 104.21.85.170
- 172.67.208.133
- 20.184.175.23
- 149.154.167.99
- 85.210.196.11
- 135.233.95.80
- 57.155.104.224
- 157.240.8.35
- 72.153.5.97
- 4.150.223.100
- 135.233.95.144
- 52.123.252.220
- 52.148.114.188
- 172.215.188.232
- 138.201.132.148
- 4.150.223.96
- 172.215.188.225
- 74.178.240.61
- 172.172.255.218
- 20.50.201.200
- 20.165.94.46
File paths
- G:\($
- Y:\bG
- m:\0HCp
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report