Boostwrite
Description
(FireEye) An in-memory-only dropper that decrypts embedded payloads using an encryption key retrieved from a remote server at runtime. FIN7 has been observed making small changes to this malware family using multiple methods to avoid traditional antivirus detection, including a BOOSTWRITE sample where the dropper was signed by a valid Certificate Authority. One of the analyzed BOOSTWRITE variants contained two payloads: Carbanak and RDFSNIFFER.
Names
Name |
---|
Boostwrite |
Category
Malware
Type
- Dropper
Information
Mitre Attack
Malpedia
Alienvault Otx
Other Information
Uuid
2df5d2a9-b01b-46ff-b2e1-d1c332db8479
Last Card Change
2020-04-22