ATT&CKReferencesMicrosoft DUBNIUM July 2016

Microsoft DUBNIUM July 2016

Microsoft. (2016, July 14). Reverse engineering DUBNIUM – Stage 2 payload analysis . Retrieved March 31, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
GroupDarkhotel

Darkhotel has collected the IP address and network adapter information from the victim’s machine.

T1027.013
Encrypted/Encoded File
GroupDarkhotel

Darkhotel has obfuscated code using RC4, XOR, and RSA.

T1082
System Information Discovery
GroupDarkhotel

Darkhotel has collected the hostname, OS version, service pack version, and the processor architecture from the victim’s machine.

T1083
File and Directory Discovery
GroupDarkhotel

Darkhotel has used malware that searched for files with specific patterns.

T1140
Deobfuscate/Decode Files or Information
GroupDarkhotel

Darkhotel has decrypted strings and imports using RC4 during execution.

T1204.002
Malicious File
GroupDarkhotel

Darkhotel has sent spearphishing emails in an attempt to lure users into clicking on a malicious attachments.

T1566.001
Spearphishing Attachment
GroupDarkhotel

Darkhotel has sent spearphishing emails with malicious RAR and .LNK attachments.

T1573.001
Symmetric Cryptography
GroupDarkhotel

Darkhotel has used AES-256 and 3DES for C2 communications.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.