MALICIOUS — 3f9b77078550cbbe17083e85527e51cb8d5260d1d580715a99c31f8f88dba38e
MALICIOUS — 3f9b77078550cbbe17083e85527e51cb8d5260d1d580715a99c31f8f88dba38e is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Dostre family. 4 of 56 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
3f9b77078550cbbe17083e85527e51cb8d5260d1d580715a99c31f8f88dba38e - SHA-1:
824ca8eeca750ce14b72bb22947987a86ac59bc7 - MD5:
451e41676254807f252db75c5a42adcf - imphash:
c5723a7c7f3ee77135900804381861ec - ssdeep:
3072:n8C0pkH7bgTClDzPfqwv9TSP0eWcmzZthYSt7Wr1g8jLrxfrz1mh/dn/a2T:hgTClrv9TSecmzzhYSt7yW8jLraJdC - TLSH:
T1B54959D84A03B407D332B20FC8D98BCD825999A564DB9560274F709E60FF57BAD9032B - Submitted as: 3f9b77078550cbbe17083e85527e51cb8d5260d1d580715a99c31f8f88dba38e
- File type: pe · Size: 393216 bytes
- Verdict: malicious (99/100) · Family: Dostre
Detections (4 of 56 engines)
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Microsoft Defender: Trojan:Win32/Dostre!atmnm
- Trellix Stinger (McAfee): Trojan-FPZA!451E41676254
- Kaspersky (KVRT): Trojan.Win32.Agent.qwidcl
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 11 weighted signals:
- Microsoft Defender flagged Trojan:Win32/Dostre!atmnm (rule
Trojan:Win32/Dostre!atmnm) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Trojan-FPZA!451E41676254 (rule
Trojan-FPZA!451E41676254) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan.Win32.Agent.qwidcl (rule
Trojan.Win32.Agent.qwidcl) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s) across 1 rule(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 6 external host(s) and 7 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1082, T1497, T1497.001 - dynamic signal, weight 0.40, confidence 0.75
- Dropped 1 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
19709 behavior events · 2 ATT&CK techniques · 18 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- www.360.cn
- icanhazip.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- settings-win.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- www.msn.com
- odc.officeapps.live.com
- assets.msn.com
- www.bing.com
- edge.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\Temp\1787383305.jpg -
628ad7e4559ea9a5f1f06e63f6d0dfdaa68c0207b7f6af5924860207b64ca0d4 - c:\users\analyst\appdata\local\temp\~b4d8\20260822002145_00000029.s -
8b271b2218af2ad76aa28ae9b355f594987b2f5ea7a1f45de7286599ea2df413 - C:\Users\analyst\AppData\Local\Temp\~BB16\C -
25f6cf57e18117e3b98ddee79b2e2a2fd7eb9b78db61f0b1e8c546cdd6eccd5d - c:\users\analyst\appdata\local\temp\~bb43\20260821172307_11.a -
176ec14a1ae2375e41372f94b9cc510c209fb8054d979100eabb44f3eb37dedc - C:\Users\analyst\AppData\Local\Temp\~BB43\20260821172304_10.a -
0191bc3334d24a06b77c8d7adcd276748a7bd4960c62d574879af052929c979b - C:\Users\analyst\AppData\Local\Temp\~31C6\20260822002141_2.a -
0c6a97c574d95fc6f2e96383a0341e744f08ed5f9745329fe09e67d9ed8620de - C:\Users\analyst\AppData\Local\Temp\~BB43\20260822002211_8.a -
c79de8ef9116e1be62b67ecb70cb7603421f5c9aceef6ac0e8f5b0d831a1dba3 - C:\ProgramData\Destro -
c2cb291f6bf259e9ec649d7c256ca4890cf672a8e6568bdf2fb422517334535e - C:\Users\analyst\AppData\Local\Temp\~BB43\20260822002204_6.a -
08b7fbb7807c1b5c253f65c4e873066645352bc56b91ffac11b58e06877e3872 - C:\Users\analyst\AppData\Local\Temp\~31C6\20260822002141_1.a -
22e0a022f3afb45e446e26bf7124431414bd24764fe7c95590cfda67a800fd2d - C:\Users\analyst\AppData\Local\Temp\~BB43\20260822002201_5.a -
61b71046cd6278852a2e82ea2262f5d3570e85b88e70af588dcdbfbc47200b83 - C:\Users\analyst\AppData\Local\Temp\~BB43\20260822002207_7.a -
8254f7de29692dd0e8ce1724b7fdfe73a95b253444935644cf9af973a228f6b8 - C:\Users\analyst\AppData\Local\Temp\tsk_0a7c196b68a54c5c.exe -
a0f347e62a24c1b4a68fcc43897633ab1ea363d8908bacdf0e3fd62060f915f3 - C:\Users\analyst\AppData\Local\Temp\1787358188.jpg -
aff9fbef40a4141e357284c60ef7a0eb6e1f7eb6b08f08f16b1cacf20b2aeb5f - C:\Users\analyst\AppData\Local\Temp\~31C6\20260822002146_4.a -
e53602617e1299f62f4f957155ff55000490be8a62ec187cdb01b43929288e5c
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://www.360.cn/status/getsign.asp
- http://icanhazip.com/
Embedded domains
- www.360.cn
- icanhazip.com
Embedded IP addresses
- 57.154.63.210
- 20.247.184.142
- 20.50.201.201
- 52.123.252.232
- 4.230.171.124
- 52.110.12.31
- 52.110.12.56
- 47.89.195.194
- 184.84.165.136
- 72.153.5.128
- 206.51.234.98
- 52.148.114.188
- 206.64.73.35
- 104.16.184.241
- 52.110.12.47
- 52.110.12.18
More Dostre samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report