S0146Windows

S0146TEXTMATE

Platforms
1
ATT&CK
14.1
References
3

Description

[TEXTMATE](https://attack.mitre.org/software/S0146) is a second-stage PowerShell backdoor that is memory-resident. It was observed being used along with [POWERSOURCE](https://attack.mitre.org/software/S0145) in February 2017. (Citation: FireEye FIN7 March 2017) Documented platforms: Windows. Catalogued in ATT&CK 14.1. 3 references curated.

Platforms· 1

Windows

References

  1. https://attack.mitre.org/software/S0146
  2. http://blog.talosintelligence.com/2017/03/dnsmessenger.html
  3. https://web.archive.org/web/20180808125108/https:/www.fireeye.com/blog/threat-research/2017/03/fin7_spear_phishing.html

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
POWERSOURCE
Software
TDTESS
Software
QUADAGENT
Software
POWERTON
Software
PowerShower
Software
POWERSTATS
Sourced from MITRE ATT&CK Enterprise 14.1. Curated by Adam Lundqvist, SQUR.