Suspected DarkHotel APT Activity Update
Common Information
Type Value
UUID 5d587e60-f8f8-41ff-b6c9-6d3fa4f1ad7a
Fingerprint ec958d1d8f3f8f89
Analysis status DONE
Considered CTI value 2
Text language
Published March 17, 2022, midnight
Added to db Sept. 26, 2022, 9:34 a.m.
Last updated Nov. 17, 2024, 11:40 p.m.
Headline Suspected DarkHotel APT activity update
Title Suspected DarkHotel APT Activity Update
Detected Hints/Tags/Attributes 109/4/36
Attributes
Details Type #Events CTI Value
Details Domain 1
behaveslike.ole2.downloader.cg
Details Domain 1
fsm-gov.com
Details Domain 1
fsmgov.org
Details Domain 1
hosterbox.com
Details Domain 3
gov.com
Details Domain 3
collab.land
Details Domain 4128
github.com
Details File 1
信息.xls
Details File 1
information.xls
Details File 249
schtasks.exe
Details File 13
syncappvpublishingserver.vbs
Details File 376
wscript.exe
Details File 1
prcjobs.vbs
Details File 1
c:\users\user\appdata\roaming\microsoft\windows\prcjobs.vbs
Details File 256
net.exe
Details Github username 27
sigmahq
Details sha1 1
6f5271275e9ac22be9ded8b9252bce064e524153
Details sha1 1
eb382c4a59b6d87e186ee269805fe2db2acf250e
Details sha1 1
69be18d343db717b6fcac9e0b52aea9a8908701d
Details sha256 2
a251ac8cec78ac4f39fc5536996bed66c3436f8c16d377922187ea61722c71f8
Details sha256 2
163c386598e1826b0d81a93d2ca0dc615265473b66d4521c359991828b725c14
Details IPv4 2
23.111.184.119
Details MITRE ATT&CK Techniques 310
T1566.001
Details MITRE ATT&CK Techniques 365
T1204.002
Details MITRE ATT&CK Techniques 137
T1059.005
Details MITRE ATT&CK Techniques 297
T1070.004
Details MITRE ATT&CK Techniques 239
T1106
Details MITRE ATT&CK Techniques 501
T1012
Details MITRE ATT&CK Techniques 480
T1053
Details MITRE ATT&CK Techniques 80
T1064
Details MITRE ATT&CK Techniques 444
T1071
Details MITRE ATT&CK Techniques 460
T1059.001
Details Url 1
https://fsm-gov.com
Details Url 1
https://github.com/sigmahq/sigma/blob/6f5271275e9ac22be9ded8b9252bce064e524153/rules/wi
Details Url 1
https://github.com/sigmahq/sigma/blob/eb382c4a59b6d87e186ee269805fe2db2acf250e/rules/wi
Details Url 1
https://github.com/sigmahq/sigma/blob/69be18d343db717b6fcac9e0b52aea9a8908701d/rules/wi