Files
MBCProject-mbc-markdown/xample-malware/gotbotkr.md
T
2020-08-21 17:49:32 -04:00

945 B

ID X0027
Aliases
Platforms Windows
Year 2019
Associated ATT&CK Software None

GotBotKR

Modified version of a publicly available backdoor name GoBot2. Modifications are mainly evasion techniques specific to South Korea. [1]

From [1], “The malware installs two instances of itself on the system. The second instance (watchdog) monitors whether the first instance is still active and reinstalls it if it has been removed from the system.”

Behaviors

Name Use
Process Discovery GotBotKR monitors whether the first instance is still active. [1]
Install Additional Program GotBotKR reinstalls its running instance if it is removed. [1]

References

[1] https://www.welivesecurity.com/2019/07/08/south-korean-users-backdoor-torrents/