Rule Info
Name
APT_MAL_DLL_Downloader_Jun25
Author
MalGamy
Description
Detects a DLL used during installation to check antivirus status, create a scheduled task to download and execute the next-stage payload via PowerShell using the system BuildNumber and AV info, and spawn a decoy PowerShell to display an image, seen being used by the DarkHotel APT group
Score
80
Date
2025-06-26
Minimum Yara
3.5.0
Rule Hash
88804350a6832e21191827a1f0359576
Tags
['MAL', 'T1059_001', 'T1053_005', 'EXE', 'APT', 'G0012', 'SCRIPT', 'FILE']
Required Modules
[]
Virustotal Matches
Antivirus Verdicts
Rating
Number of Samples
Malicious (>= 10 engines)
1
Suspicious (< 10 engines)
3
Clean (0 engines)
0
Rule Matches
Timestamp
Positives
Total
Hash
VT
