Names | DRAWSTRING | |
Category | Malware | |
Type | Downloader, Reconnaissance, Info stealer | |
Description | (Mandiant) A downloader, which Mandiant tracks as DRAWSTRING, has some internal recon functionality. While primarily providing FIN13 the ability to download and execute arbitrary files, DRAWSTRING will also execute systeminfo.exe and upload that information to a command and control (C2) server. | |
Information | <https://www.mandiant.com/resources/fin13-cybercriminal-mexico> |
Last change to this tool card: 26 December 2021
Download this tool card in JSON format
Changed | Name | Country | Observed | ||
APT groups | |||||
FIN13 | [Unknown] | 2016 |
1 group listed (1 APT, 0 other, 0 unknown)
Digital Service Security Center Follow us on |
Report incidents |
|
+66 (0)2-123-1227 | ||
[email protected] |