Files
MBCProject-mbc-markdown/xample-malware/terminator.md
T
2020-08-21 17:49:32 -04:00

890 B

ID X0021
Aliases
Platforms Windows
Year 2013
Associated ATT&CK Software None

Terminator

A remote access tool (RAT).

Behaviors

Name Use
Sandbox Detection The Terminator rat evades a sandbox by not executing until after a reboot. Most sandboxes don't reboot during an analysis. [1]
Registry Run Keys / Startup Folder Sets "2019" as Windows' startup folder by modifying a registry value. [1]
File Deletion The malicious executable deletes itself after it has dropped other executable files.

References

[1] https://www.fireeye.com/content/dam/fireeye-www/current-threats/pdfs/pf/file/fireeye-hot-knives-through-butter.pdf