PULSE NAME
Darkhotel’s attacks in 2015
WHITE AlienVault 2015-08-10 Modified: 2015-08-10
65
IOCs
HIGH VOLUME
Darkhotel APT attacks dated 2014 and earlier are characterized by the misuse of stolen certificates, the deployment of .hta files with multiple techniques, and the use of unusual methods like the infiltration of hotel Wi-Fi to place backdoors in targets’ systems. In 2015, many of these techniques and activities remain in use. However, in addition to new variants of malicious .hta, we find new victims, .rar attachments with RTLO spearphishing, and the deployment of a 0day from Hacking Team. The Darkhotel APT continues to spearphish targets around the world, with a wider geographic reach than its previous botnet buildout and hotel Wi-Fi attacks. Some of the targets are diplomatic or have strategic commercial interests.
Indicators of Compromise (65)
All domain URL hostname FileHash-MD5 CVE
TYPEINDICATORDESCRIPTIONCREATED
domain unionnewsreport.net 2015-08-10
domain office-revision.com 2015-08-10
domain saytargetworld.net 2015-08-10
domain eonlineworld.net 2015-08-10
domain tisone360.org 2015-08-10
domain error-page.net 2015-08-10
domain tisone360.com 2015-08-10
domain thewordusrapid.com 2015-08-10
URL http://tisone360.com/img_h/ims2/icon.jpg 2015-08-10
URL http://tisone360.com/htdoc/page1/page.html 2015-08-10
URL http://tisone360.com/noname/minky/face.php 2015-08-10
URL http://www.openofficev.info/dec98/unzip.js 2015-08-10
URL http://www.openofficev.info/decod9/unzip.js 2015-08-10
URL http://www.openofficev.info/open99/office32 2015-08-10
URL http://tisone360.com/htdoc/ImageView.hta 2015-08-10
URL http://sendspace.servermsys.com/downloader.hta 2015-08-10
URL http://tisone360.com/img_h/ims2/1.php 2015-08-10
URL http://photo.storyonboard.net/wmpsrx64 2015-08-10
URL http://photo.storyonboard.net/readme.php 2015-08-10
URL http://error-page.net/update/load.php 2015-08-10
URL http://sendspace.servermsys.com/wnctprx 2015-08-10
URL http://daily.enewsbank.net/newsviewer.hta 2015-08-10
URL http://unionnewsreport.net/aeroflot_bonus/ticket.php 2015-08-10
URL http://www.openofficev.info/xopen88/office2 2015-08-10
URL http://tisone360.com/noname/img/movie.swf 2015-08-10
URL http://saytargetworld.net/season/nextpage.php 2015-08-10
URL http://daily.enewsbank.net/wmpsrx64 2015-08-10
URL http://photo.storyonboard.net/photoviewer.hta 2015-08-10
hostname sendspace.servermsys.com 2015-08-10
hostname daily.enewsbank.net 2015-08-10
hostname www.openofficev.info 2015-08-10
hostname photo.storyonboard.net 2015-08-10
hostname online.newssupply.net 2015-08-10
FileHash-MD5 021685613fb739dec7303247212c3b09 2015-08-10
FileHash-MD5 5c74db6f755555ea99b51e1c68e796f9 2015-08-10
FileHash-MD5 852a9411a949add69386a72805c8cb05 2015-08-10
FileHash-MD5 fa67142728e40a2a4e97ccc6db919f2b 2015-08-10
FileHash-MD5 2899f4099c76232d6362fd62ab730741 2015-08-10
FileHash-MD5 2dee887b20a06b8e556e878c62e46e13 2015-08-10
FileHash-MD5 d965a5b3548047da27b503029440e77f 2015-08-10
FileHash-MD5 be59994b5008a0be48934a9c5771dfa5 2015-08-10
FileHash-MD5 61cc019c3141281073181c4ef1f4e524 2015-08-10
FileHash-MD5 e29693ce15acd552f1a0435e2d31d6df 2015-08-10
FileHash-MD5 214709aa7c5e4e8b60759a175737bb2b 2015-08-10
FileHash-MD5 33e278c5ba6bf1a545d45e17f7582512 2015-08-10
FileHash-MD5 da0717899e3ccc1ba0e8d32774566219 2015-08-10
FileHash-MD5 dc0de14d9d36d13a6c8a34b2c583e70a 2015-08-10
FileHash-MD5 da360e94e60267dce08e6d47fc1fcecc 2015-08-10
FileHash-MD5 3d2e941ac48ae9d79380ca0f133f4a49 2015-08-10
FileHash-MD5 fc78b15507e920b3ee405f843f48a7b3 2015-08-10
FileHash-MD5 39562e410bc3fb5a30aca8162b20bdd0 2015-08-10
FileHash-MD5 c3ae70b3012cc9b5c9ceb060a251715a 2015-08-10
FileHash-MD5 009d85773d519a9a97129102d8116305 2015-08-10
FileHash-MD5 a7e78fd4bf305509c2fc1b3706567acd 2015-08-10
FileHash-MD5 61637a0637fb25c53f396c305efa5dc5 2015-08-10
FileHash-MD5 42a837c4433ae6bd7490baec8aeb5091 2015-08-10
FileHash-MD5 560d68c31980c26d2adab7406b61c651 2015-08-10
FileHash-MD5 5e01b8bc78afc6ecb3376c06cbceb680 2015-08-10
FileHash-MD5 1ee3dfce97ab318b416c1ba7463ee405 2015-08-10
FileHash-MD5 fef8fda27deb3e950ba1a71968ec7466 2015-08-10
FileHash-MD5 a07124b65a76ee7d721d746fd8047066 2015-08-10
FileHash-MD5 e85e0365b6f77cc2e9862f987b152a89 2015-08-10
FileHash-MD5 6b9e9b2dc97ff0b26a8a61ba95ca8ff6 2015-08-10
FileHash-MD5 b1f56a54309147b07dda54623fecbb89 2015-08-10
CVE CVE-2014-0497 2015-08-10