APT_MAL_DLL_Downloader_Jun25

Rule Info

Name
APT_MAL_DLL_Downloader_Jun25
Author
MalGamy
Description
Detects a DLL used during installation to check antivirus status, create a scheduled task to download and execute the next-stage payload via PowerShell using the system BuildNumber and AV info, and spawn a decoy PowerShell to display an image, seen being used by the DarkHotel APT group
Score
80
Date
2025-06-26
Minimum Yara
3.5.0
Rule Hash
88804350a6832e21191827a1f0359576
Tags
['MAL', 'T1059_001', 'T1053_005', 'EXE', 'APT', 'G0012', 'SCRIPT', 'FILE']
Required Modules
[]

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
1
Suspicious (< 10 engines)
3
Clean (0 engines)
0

Rule Matches

Timestamp
Positives
Total
Hash
VT
2026-05-05 15:07:44
10
71
f29e3f32d3de868b3aa33368cbca5c74725165ad42cef680b81c0b7c3bc63896
2026-03-28 07:30:15
6
54
04860ba4f44bd859a3163be62007ab20894200893fb91fa3e3ab13d782229649
2025-11-06 07:45:19
9
73
d794df407ca288d054714fde8254b50a09b1e6d9e1076e22e7acc461a8566319
2025-07-11 13:31:01
6
64
d172e82e4a04a5ece8e50eda30dd23384a1c5d6d409ad6692e0f2db8d15c4755

Rule Matches per Month (last 24 months)