
One Static Token Ties Four Rotating DarkHotel C2 Domains Together
An unsigned, Adobe-disguised downloader (Catch.exe/update.exe) carries virtualization, sandbox, and debugger evasion before beaconing to four separate dynamic-DNS domains — all hitting the identical /bin/home/home.php path with the same static parameter, revealing one reused C2 backend behind disposable fronts.
An unsigned 2.4MB Windows executable masquerading as an Adobe updater (catalogued as 672c82c1…d26b65ef, and referred to here as the Catch.exe downloader after its internal name) carries a full anti-analysis stack — virtualization and sandbox checks [T1497, T1497.002, T1497.003], debugger evasion [T1622], and code injection into another process's window memory [T1055.011] — before it ever reaches out to command infrastructure.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read