ATT&CKReferencesLastline DarkHotel Just In Time Decryption Nov 2015

Lastline DarkHotel Just In Time Decryption Nov 2015

Arunpreet Singh, Clemens Kolbitsch. (2015, November 5). Defeating Darkhotel Just-In-Time Decryption. Retrieved April 15, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1124
System Time Discovery
GroupDarkhotel

Darkhotel malware can obtain system time from a compromised host.

T1497
Virtualization/Sandbox Evasion
GroupDarkhotel

Darkhotel malware has employed just-in-time decryption of strings to evade sandbox detection.

T1497.001
System Checks
GroupDarkhotel

Darkhotel malware has used a series of checks to determine if it's being analyzed; checks include the length of executable names, if a filename ends with .Md5.exe, and if the program is executed from the root of the C:\ drive, as well as checks for sandbox-related libraries.

T1497.002
User Activity Based Checks
GroupDarkhotel

Darkhotel has used malware that repeatedly checks the mouse cursor position to determine if a real user is on the system.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.