Boostwrite

Description

(FireEye) An in-memory-only dropper that decrypts embedded payloads using an encryption key retrieved from a remote server at runtime. FIN7 has been observed making small changes to this malware family using multiple methods to avoid traditional antivirus detection, including a BOOSTWRITE sample where the dropper was signed by a valid Certificate Authority. One of the analyzed BOOSTWRITE variants contained two payloads: Carbanak and RDFSNIFFER.

Names

Name
Boostwrite

Category

Malware

Type

  • Dropper

Information

Mitre Attack

Malpedia

Alienvault Otx

Other Information

Uuid

2df5d2a9-b01b-46ff-b2e1-d1c332db8479

Last Card Change

2020-04-22