logo

Reverse-engineering DUBNIUM

ID: 01ccd914-c459-42c7-ad81-dded11edfdee

STIX ID: report--01ccd914-c459-42c7-ad81-dded11edfdee

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2016-06-30

Last Modified Date: 2016-06-30

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report analyzes the DUBNIUM (DarkHotel-linked) first-stage downloader, describing how the binary disguises itself as an SSH/OpenSSL tool, encodes and wipes strings from memory, performs extensive anti-analysis and geolocation/environment checks, and uses mshta.exe (after distribution via a Flash zero-day or spear-phishing LNK) to retrieve a second-stage payload; the report includes numerous SHA1 IoCs and implementation details useful for detection and reverse engineering.