Skip to content

Latest commit

 

History

History
27 lines (22 loc) · 757 Bytes

alter-install-location.md

File metadata and controls

27 lines (22 loc) · 757 Bytes
ID B0027
Objective(s) Defense Evasion
Related ATT&CK Technique None

Alternative Installation Location

Malware may install itself not as a file on the hard drive. [1]

Methods

Name ID Description
Fileless Malware B0027.001 Stores itself in memory.
Registry Install B0027.002 Stores itself in the Windows registry.

Malware Examples

Name Date Description
Kovter 2016 Stores malware files in the Registry instead of the hard drive. [1]

References

[1] https://www.bleepingcomputer.com/virus-removal/remove-kovter-trojan