GAMUT-BOTNET

GAMUT-BOTNETGamut Botnet

Description

Gamut was found to be downloaded by a Trojan Downloader that arrives as an attachment from a spam email message. The bot installation is quite simple. After the malware binary has been downloaded, it launches itself from its current directory, usually the Windows %Temp% folder and installs itself as a Windows service. The malware utilizes an anti-VM (virtual machine) trick and terminates itself if it detects that it is running in a virtual machine environment. The bot uses INT 03h trap sporadically in its code, an anti-debugging technique which prevents its code from running within a debugger environment. It can also determine if it is being debugged by using the Kernel32 API - IsDebuggerPresent function.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
Gootkit
Software
Sibot
Software
Spamthru
Software
gh0st
Software
Trik Spam Botnet
Software
BANGAT
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.