Skip to content

Botnet

PS1Bot

According to Cisco Talos, this is multi-stage malware framework, implemented in PowerShell and C#, that possesses robust functionality, including the ability to deliver follow-on modules including an

PS1Bot is a PHP botnet.

Background

Cisco Talos characterizes this as a multi-stage framework written in PowerShell and C# with broad capabilities, among them delivering additional modules such as an information stealer, a keylogger, a screen-capture component, and others. It also maintains persistence so it survives reboots. The framework is built to leave as few traces as possible on a host, loading and running its modules entirely in memory rather than writing them to disk. Talos named the PowerShell-based threat “PS1Bot” because its design and implementation resemble the AHK Bot family.


Source: Malpedia (Fraunhofer FKIE).