Phase Bot – A Fileless Rootkit (Part 1) – MalwareTech
Common Information
Type Value
UUID f756c35f-b840-4e34-95d4-db78ee0084c1
Fingerprint 8c2f888385f779e0
Analysis status DONE
Considered CTI value 0
Text language
Published Dec. 11, 2014, 9:51 p.m.
Added to db Jan. 18, 2023, 11:28 p.m.
Last updated Nov. 18, 2024, 1:38 a.m.
Headline Phase Bot – A Fileless Rootkit (Part 1)
Title Phase Bot – A Fileless Rootkit (Part 1) – MalwareTech
Detected Hints/Tags/Attributes 30/1/4
Attributes
Details Type #Events CTI Value
Details Domain 372
wscript.shell
Details File 1018
rundll32.exe
Details File 1209
powershell.exe
Details Windows Registry Key 1
HKCUSoftwareMicrosoftActive