Published on: 22 May, 2018
Darkhotel (APT-C-06) actor known to perform cyber espionage activities against corporate executives,
defense industry, electronics industry via Wi-Fi infrastructure in hotels coupling with whaling
(high-level spear phishing) techniques. Researchers have revealed recent activities by the gang.
A list of reported IOC's is listed for your perusal and action.
IOC's:
- domain100100011100[dot]com
- domain37281933[dot]net
- domaingw-engine[dot]com
- domainhelp-software[dot]org
- domainluriasstereo[dot]net
- domainmakethemeasier[dot]com
- domainstar--co[dot]net
- domainwindows-updater[dot]net
- domainursbusiness[dot]com
URL's:
- http://100100011100[dot]com/_sexygirl/userinfo.php
- http://37281933[dot]net/_radiostar/kill.php
- http://gw-engine[dot]com/i33po/profile.php
- http://help-software[dot]org/i33po/profile.php
- http://luriasstereo[dot]net/_sexygirl/userinfo.php
- http://makethemeasier[dot]com/TT2/config.php
- http://star--co[dot]net/_sexygirl/userinfo.php
- http://windows-updater[dot]net/_radiostar/kill.php
File System:
- File system %temp%\taskhost.exe
- File system %temp%\chrome_frame_helper.dll
- File system %ALLUSERSPROFILE%\AU50FE1D
MD5 Hash:
- FileHash-MD5060808e4df4fe5a25d3abb05dccd5119
- FileHash-MD50b7d49d9e56c39ac7b253205a0805d57
- FileHash-MD51fedb9693fd1677b5015a6ef72d6c6f4
- FileHash-MD523db00a35ef7dc511a27d229313d4e27
- FileHash-MD534243444bebe430a85b372eaa78f0b67
- FileHash-MD546a52215e44a9814c6c8e96c973181ac
- FileHash-MD54a5eba093461e4f19201b3406a3e5188
- FileHash-MD558f80d3ef27f6a424a5ace8c032fad28
- FileHash-MD56075cbb9b522dc71a46cadd18a1afef4
- FileHash-MD583a24589431f191cdde110ef64c21568
- FileHash-MD5840b73bef7c38e1266faac4eb3f00447
- FileHash-MD59badf32c51938cf61e7b37879a4fb349
- FileHash-MD5a2a0f725dda95d7ec79d0621e1b7a5b2
- FileHash-MD5c6d68c4f7f059f55894e5b57440b5dcf
- FileHash-MD5cba213e68cb6af25ae7303efb8629f14
- FileHash-MD5dc97cb0c195f4f1cf82429bba9cc007f
- FileHash-MD5dd2b0d222167406279a4ca91fd935591
- FileHash-MD5e0dceda02df50e974d9e51bb6c7dac84
- FileHash-MD500f048d0fbb3d6d1bf0c3e0c910c1805
- FileHash-MD508fd1e9374266cc0d9304757913ddac9
- FileHash-MD50a5aac8e9c17ecaa7de4b7949198321c
- FileHash-MD51b982fd90168f50d0f6b5c72461a48cc
- FileHash-MD528e434a304e99d3b01ae8ac557c8f256
- FileHash-MD53244a208715e1a4ced1e626d74fe7fd2
- FileHash-MD539aba73891b2c6bc96a34dd28df41358
- FileHash-MD53dab0965ab27825ac10b3d8f50db86b6
- FileHash-MD53dee6f79039eaa22319d1990540929b2
- FileHash-MD5573a67b5dda7346f338f1f380b300e7b
- FileHash-MD562ae0da3a12be98e641828d11a990bce
- FileHash-MD57abd7a9ee4eb8a89b5bd423612f87a6d
- FileHash-MD5842366795efde36c321059db44be6163
- FileHash-MD58d5271ee2d503e697232ada1e3775a85
- FileHash-MD592480c1a771d99dbef00436e74c9a927
- FileHash-MD5a0ef9bf38cd759fd6ddd1f6f93406284
- FileHash-MD5a1179f2fc248ccc2f9eafc6d04928515
- FileHash-MD5c100213f5a961039ed35a1e776fc65c7
- FileHash-MD5da3255aa260090589543a807aeaa3894
- FileHash-MD5e02fad27032a0373812100c8d7b0959b
- FileHash-MD5e884f0cb851137bd73b2eb70a110655b