MALICIOUS — 5ea4891bb4d8c99ed1a6607b4cd690c0b5a8471a367de2fb69c02e4c6aa35012
MALICIOUS — 5ea4891bb4d8c99ed1a6607b4cd690c0b5a8471a367de2fb69c02e4c6aa35012 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Dostre family. 4 of 56 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
5ea4891bb4d8c99ed1a6607b4cd690c0b5a8471a367de2fb69c02e4c6aa35012 - SHA-1:
39bd8a72fd3aef9022b2cf2aa61951ccdd454a20 - MD5:
0d5f46e014d6ac4d151c1af7b1d42d00 - imphash:
c5723a7c7f3ee77135900804381861ec - ssdeep:
3072:n8CRxGsqEqUelVKVkX4s///ff2U4YP0v5ePYF8WN12QIzULD:fkWtKKVkzOIsvGYF8G1WULD - TLSH:
T12E495ADB7B2AB128C53666353C1CA7DC51839DB2A06E16011703274C2CFB57BAED1AE4 - Submitted as: 5ea4891bb4d8c99ed1a6607b4cd690c0b5a8471a367de2fb69c02e4c6aa35012
- File type: pe · Size: 393216 bytes
- Verdict: malicious (99/100) · Family: Dostre
Detections (4 of 56 engines)
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Microsoft Defender: Trojan:Win32/Dostre!atmnm
- Trellix Stinger (McAfee): Trojan-FPZA!0D5F46E014D6
- Kaspersky (KVRT): Trojan.Win32.Agent.qwidcl
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 11 weighted signals:
- Microsoft Defender flagged Trojan:Win32/Dostre!atmnm (rule
Trojan:Win32/Dostre!atmnm) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Trojan-FPZA!0D5F46E014D6 (rule
Trojan-FPZA!0D5F46E014D6) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan.Win32.Agent.qwidcl (rule
Trojan.Win32.Agent.qwidcl) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s) across 1 rule(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 5 external host(s) and 22 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1082, T1497, T1497.001 - dynamic signal, weight 0.40, confidence 0.75
- Dropped 1 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
15872 behavior events · 2 ATT&CK techniques · 23 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- www.360.cn
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- icanhazip.com
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
Dropped files
- C:\Users\analyst\AppData\Local\Temp\~BB43\20260826040708_7.a -
1d044a2467a7567afbb2b0061c2a617d038bbbaf158c69ed516dd395700491bc - C:\Users\analyst\AppData\Local\Temp\1787717296.jpg -
0d055cdf00ef97fd4fe831deaad1dc7f39f9219c61f2e7a448377bd9d066c0e8 - C:\Users\analyst\AppData\Local\Temp\1787742406.jpg -
0617ee660987b1b57bb058e14b04e1fcdf4ef3693b1dd9e0cac8f1297af8f18a - C:\Users\analyst\AppData\Local\Temp\~31C6\20260825210828_14.a -
017fa9f2fa6c782c0aff210e17a4e2db234b21ea5f22dccc58960ebb5fd11c08 - C:\Users\analyst\AppData\Local\Temp\~BB43\20260826040701_5.a -
1ff570046abbe184fec74c55d5624c31126a8b99cc976ec4cabc586d8121a4b3 - C:\Users\analyst\AppData\Local\Temp\~BB43\20260825210814_10.a -
e8e6e3d1bce2f04423c4333928328b963663d74f43f5594ee0f2074cc38e96ce - C:\Users\analyst\AppData\Local\Temp\~BB43\20260825210824_13.a -
fff916aa7411daac2be2c204ef48c43da127989f47a1ab1f101d07173ca4edf5 - C:\Users\analyst\AppData\Local\Temp\~BB43\20260825210820_12.a -
262975140de5c94a423f23a420245799837dc78a9690b3f56a9c03335d33e871 - C:\Users\analyst\AppData\Local\Temp\~BB43\20260826040705_6.a -
4289dbc12c741a6ae20b86b7fbbc0c8014b7409c2622ab290e54b1eec02f3ac8 - C:\Users\analyst\AppData\Local\Temp\~BB43\20260826040715_9.a -
bb230a00b12570f6879d9f401db0906009177314e66db5bba902f078dba7f724 - C:\Users\analyst\AppData\Local\Temp\~BB43\20260826040712_8.a -
94e90942e56430872ccd92b8cd6bc5705721c38ec0ae7e6a2087cc751bc533ac - C:\Users\analyst\AppData\Local\Temp\tsk_bbb5ac9a234f4cef.exe -
fdd558752e2fdeb25a9f2d6c0c112c6cfe5748f9baebf917aaf3d0b3d3c245e2 - C:\ProgramData\Destro -
c2cb291f6bf259e9ec649d7c256ca4890cf672a8e6568bdf2fb422517334535e - c:\users\analyst\appdata\local\temp\~b4d8\20260826040649_00000029.s -
0a8b2b1547550434aa69cc2beb37017e3adf71cfbf4a6c747c1da0c9a0a74ff7 - C:\Users\analyst\AppData\Local\Temp\~31C6\20260826040642_2.a -
0b877042474aa986a9510ed2894ac816fe62d3502da23dc587b8196f0ff9731f
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://www.360.cn/status/getsign.asp
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
- http://icanhazip.com/
Embedded domains
- www.360.cn
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- icanhazip.com
Embedded IP addresses
- 51.104.15.252
- 4.230.171.124
- 48.211.4.16
- 85.210.193.152
- 74.178.240.51
- 20.247.184.142
- 4.150.223.102
- 74.178.76.128
- 104.18.33.89
- 52.110.12.31
- 52.110.12.52
- 47.89.195.194
- 4.247.188.233
- 207.0.190.71
- 52.148.114.188
- 104.16.185.241
- 72.145.35.104
- 92.223.78.30
- 52.110.12.54
- 210.103.6.8
- 52.110.12.47
More Dostre samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report