Files
MBCProject-mbc-markdown/xample-malware/gotbotkr.md
T
Desiree Beck 2661c77bc7 fix links
2019-09-17 19:17:58 -04:00

1.2 KiB

ID X0027
Aliases
Platforms Windows
Year 2019

GotBotKR

Modified version of a publicly available backdoor name GoBot2. Modifications are mainly evasion techniques specific to South Korea. [1]

From [1], “The malware installs two instances of itself on the system. The second instance (watchdog) monitors whether the first instance is still active and reinstalls it if it has been removed from the system.”

Behaviors

Name Use
Redundant Access GotBotKR installs two instances of itself. [1]
Process Discovery GotBotKR monitors whether the first instance is still active. [1]
Install Additional Program GotBotKR reinstalls its running instance if it is removed. [1]

References

[1] https://www.welivesecurity.com/2019/07/08/south-korean-users-backdoor-torrents/