ATT&CKReferencesMicrosoft DUBNIUM June 2016

Microsoft DUBNIUM June 2016

Microsoft. (2016, June 9). Reverse-engineering DUBNIUM. Retrieved March 31, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1036.005
Match Legitimate Resource Name or Location
GroupDarkhotel

Darkhotel has used malware that is disguised as a Secure Shell (SSH) tool.

T1105
Ingress Tool Transfer
GroupDarkhotel

Darkhotel has used first-stage payloads that download additional malware from C2 servers.

T1203
Exploitation for Client Execution
GroupDarkhotel

Darkhotel has exploited Adobe Flash vulnerability CVE-2015-8651 for execution.

T1497.001
System Checks
GroupDarkhotel

Darkhotel malware has used a series of checks to determine if it's being analyzed; checks include the length of executable names, if a filename ends with .Md5.exe, and if the program is executed from the root of the C:\ drive, as well as checks for sandbox-related libraries.

T1518.001
Security Software Discovery
GroupDarkhotel

Darkhotel has searched for anti-malware strings and anti-virus processes running on the system.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.