{
  "modified": "2024-11-17T16:24:43.289Z",
  "name": "BOOTRASH",
  "description": "[BOOTRASH](https://attack.mitre.org/software/S0114) is a [Bootkit](https://attack.mitre.org/techniques/T1542/003) that targets Windows operating systems. It has been used by threat actors that target the financial sector.(Citation: Mandiant M Trends 2016)(Citation: FireEye Bootkits)(Citation: FireEye BOOTRASH SANS)",
  "is_family": true,
  "x_mitre_platforms": [
    "Windows"
  ],
  "x_mitre_deprecated": false,
  "x_mitre_domains": [
    "enterprise-attack"
  ],
  "x_mitre_version": "1.1",
  "x_mitre_contributors": [
    "Christopher Glyer, Mandiant, @cglyer"
  ],
  "x_mitre_aliases": [
    "BOOTRASH"
  ],
  "type": "malware",
  "spec_version": "2.1",
  "id": "malware--da2ef4a9-7cbe-400a-a379-e2f230f28db3",
  "created": "2017-05-31T21:33:08.292Z",
  "created_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
  "revoked": false,
  "external_references": [
    {
      "source_name": "mitre-attack",
      "url": "https://attack.mitre.org/software/S0114",
      "external_id": "S0114"
    },
    {
      "source_name": "FireEye Bootkits",
      "description": "Andonov, D., et al. (2015, December 7). Thriving Beyond The Operating System: Financial Threat Group Targets Volume Boot Record. Retrieved May 13, 2016.",
      "url": "https://www.fireeye.com/blog/threat-research/2015/12/fin1-targets-boot-record.html"
    },
    {
      "source_name": "FireEye BOOTRASH SANS",
      "description": "Glyer, C.. (2017, June 22). Boot What?. Retrieved November 17, 2024.",
      "url": "https://web.archive.org/web/20190926040727/https://www.sans.org/cyber-security-summit/archives/file/summit-archive-1498163766.pdf"
    },
    {
      "source_name": "Mandiant M Trends 2016",
      "description": "Mandiant. (2016, February 25). Mandiant M-Trends 2016. Retrieved November 17, 2024.",
      "url": "https://web.archive.org/web/20211024160454/https://www.fireeye.com/content/dam/fireeye-www/current-threats/pdfs/rpt-mtrends-2016.pdf"
    }
  ],
  "object_marking_refs": [
    "marking-definition--fa42a846-8d90-4e51-bc29-71d5b4802168"
  ],
  "x_mitre_attack_spec_version": "3.2.0",
  "x_mitre_modified_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5"
}