Microsoft. (2016, July 14). Reverse engineering DUBNIUM – Stage 2 payload analysis . Retrieved March 31, 2021.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
GroupDarkhotel | Darkhotel has collected the IP address and network adapter information from the victim’s machine. |
| T1027.013 Encrypted/Encoded File |
GroupDarkhotel | Darkhotel has obfuscated code using RC4, XOR, and RSA. |
| T1082 System Information Discovery |
GroupDarkhotel | Darkhotel has collected the hostname, OS version, service pack version, and the processor architecture from the victim’s machine. |
| T1083 File and Directory Discovery |
GroupDarkhotel | Darkhotel has used malware that searched for files with specific patterns. |
| T1140 Deobfuscate/Decode Files or Information |
GroupDarkhotel | Darkhotel has decrypted strings and imports using RC4 during execution. |
| T1204.002 Malicious File |
GroupDarkhotel | Darkhotel has sent spearphishing emails in an attempt to lure users into clicking on a malicious attachments. |
| T1566.001 Spearphishing Attachment |
GroupDarkhotel | Darkhotel has sent spearphishing emails with malicious RAR and .LNK attachments. |
| T1573.001 Symmetric Cryptography |
GroupDarkhotel | Darkhotel has used AES-256 and 3DES for C2 communications. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.