SYMBOLCOMMON_NAMEaka. SYNONYMS
win.dohdoor (Back to overview)

DohDoor

VTCollection    

According to Cisco Talos, Dohdoor is a 64-bit Windows DLL backdoor/loader, written in C/C++, that is delivered via DLL sideloading through legitimate Windows executables launched by batch and PowerShell scripts. It uses DNS-over-HTTPS (DoH) to Cloudflare’s DNS service to resolve its C2 domains, then establishes an HTTPS tunnel to Cloudflare’s edge as a front for the hidden C2, making all traffic look like normal HTTPS to reputable cloud infrastructure. Dohdoor downloads, decrypts (custom XOR-SUB, position-dependent cipher with SIMD), and reflectively executes additional payloads (likely Cobalt Strike) via process hollowing into hardcoded Windows binaries such as OpenWith.exe and ImagingDevices.exe. To stay stealthy, it relies on hash-based API resolution, encrypted C2, EDR bypass via ntdll syscall unhooking, and infrastructure/hostnames that mimic Windows updates and security tools.

References
2026-02-26 ⋅ Cisco Talos ⋅ Alex Karkins, Chetan Raghuprasad
New Dohdoor malware campaign targets education and health care
DohDoor
Yara Rules
[TLP:WHITE] win_dohdoor_auto (20260917 | Detects win.dohdoor.)
rule win_dohdoor_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.dohdoor."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dohdoor"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 4c2bc3 488bd3 488d4c2450 e8???????? 90 488d5701 0f57c0 }
            // n = 7, score = 100
            //   4c2bc3               | mov                 ebp, ecx
            //   488bd3               | dec                 eax
            //   488d4c2450           | test                eax, eax
            //   e8????????           |                     
            //   90                   | je                  0x171d
            //   488d5701             | dec                 eax
            //   0f57c0               | mov                 edx, dword ptr [eax + 0x18]

        $sequence_1 = { 8bd7 4c8bf7 4c8d2571e1feff 4a8d0cfd3e000000 4b038cdc80e40200 403839 740e }
            // n = 7, score = 100
            //   8bd7                 | mov                 edi, dword ptr [ebp + 0x208]
            //   4c8bf7               | dec                 eax
            //   4c8d2571e1feff       | mov                 ecx, edi
            //   4a8d0cfd3e000000     | sub                 edi, eax
            //   4b038cdc80e40200     | jne                 0x47
            //   403839               | dec                 eax
            //   740e                 | mov                 ebx, dword ptr [esp + 0x90]

        $sequence_2 = { 4c8bf7 4c8d2571e1feff 4a8d0cfd3e000000 4b038cdc80e40200 }
            // n = 4, score = 100
            //   4c8bf7               | dec                 eax
            //   4c8d2571e1feff       | mov                 ebx, dword ptr [esp + 0x42c8]
            //   4a8d0cfd3e000000     | dec                 eax
            //   4b038cdc80e40200     | add                 esp, 0x4270

        $sequence_3 = { 488d1d87530200 488d3d80530200 eb12 488b03 4885c0 7406 ff15???????? }
            // n = 7, score = 100
            //   488d1d87530200       | dec                 eax
            //   488d3d80530200       | lea                 ecx, [0x163a4]
            //   eb12                 | dec                 eax
            //   488b03               | lea                 eax, [0x16056]
            //   4885c0               | dec                 eax
            //   7406                 | lea                 ecx, [0x1627f]
            //   ff15????????         |                     

        $sequence_4 = { d3e8 4189451c 49895508 0fb60a 83e10f 4a0fbe8419b0040200 428a8c19c0040200 }
            // n = 7, score = 100
            //   d3e8                 | imul                ecx, edx
            //   4189451c             | inc                 ecx
            //   49895508             | add                 ecx, ebx
            //   0fb60a               | movsx               eax, dl
            //   83e10f               | inc                 ecx
            //   4a0fbe8419b0040200     | imul    ecx, edx
            //   428a8c19c0040200     | inc                 ecx

        $sequence_5 = { 85c0 0f8567010000 4c8d059d1b0100 488bd7 488bcb e8???????? 85c0 }
            // n = 7, score = 100
            //   85c0                 | dec                 eax
            //   0f8567010000         | mov                 ecx, edi
            //   4c8d059d1b0100       | je                  0x774
            //   488bd7               | xor                 ebx, ebx
            //   488bcb               | dec                 eax
            //   e8????????           |                     
            //   85c0                 | test                edi, edi

        $sequence_6 = { eb1d 4885ff 750b 488d0d7c280100 }
            // n = 4, score = 100
            //   eb1d                 | mov                 esp, dword ptr [ebp - 0x80]
            //   4885ff               | dec                 ebp
            //   750b                 | add                 edi, esi
            //   488d0d7c280100       | inc                 ecx

        $sequence_7 = { 89542420 4c8d0dd651feff 4c8b4570 8b5568 488b4d60 }
            // n = 5, score = 100
            //   89542420             | lea                 ecx, [0x1e625]
            //   4c8d0dd651feff       | xorps               xmm0, xmm0
            //   4c8b4570             | dec                 eax
            //   8b5568               | sub                 esp, 0x20
            //   488b4d60             | dec                 eax

        $sequence_8 = { e8???????? 4885c0 0f84be000000 488b5018 4885d2 0f84b1000000 }
            // n = 6, score = 100
            //   e8????????           |                     
            //   4885c0               | dec                 esp
            //   0f84be000000         | lea                 eax, [esp + 0x48]
            //   488b5018             | dec                 eax
            //   4885d2               | lea                 edx, [0x11549]
            //   0f84b1000000         | dec                 eax

        $sequence_9 = { 498bcf 0f4d7b44 4863f7 4c8bc6 e8???????? 8b4344 }
            // n = 6, score = 100
            //   498bcf               | dec                 eax
            //   0f4d7b44             | arpl                word ptr [esi + 0x3c], ax
            //   4863f7               | cmp                 eax, 0x4200
            //   4c8bc6               | jmp                 0x42
            //   e8????????           |                     
            //   8b4344               | dec                 eax

    condition:
        7 of them and filesize < 413696
}
Download all Yara Rules