Reverse-engineering DUBNIUM
ID: 01ccd914-c459-42c7-ad81-dded11edfdee
STIX ID: report--01ccd914-c459-42c7-ad81-dded11edfdee
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2016-06-30
Last Modified Date: 2016-06-30
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report analyzes the DUBNIUM (DarkHotel-linked) first-stage downloader, describing how the binary disguises itself as an SSH/OpenSSL tool, encodes and wipes strings from memory, performs extensive anti-analysis and geolocation/environment checks, and uses mshta.exe (after distribution via a Flash zero-day or spear-phishing LNK) to retrieve a second-stage payload; the report includes numerous SHA1 IoCs and implementation details useful for detection and reverse engineering.
