Windows_Trojan_Trickbot_07239dad
Description
Targets vncDll64.dll module containing remote control VNC functionality
Query · yara
strings:
$a1 = "C:\\Users\\MaxMikhaylov\\Documents\\Visual Studio 2010\\MMVNC.PROXY\\VNCSRV\\x64\\Release\\VNCSRV.pdb" ascii fullword
$a2 = "vncsrv.dll" ascii fullword
$a3 = "-new -noframemerging http://www.google.com" ascii fullword
$a4 = "IE.HTTP\\shell\\open\\command" ascii fullword
$a5 = "EDGE\\shell\\open\\command" ascii fullword
$a6 = "/K schtasks.exe |more" ascii fullword
$a7 = "<moduleconfig><needinfo name=\"id\"/><needinfo name=\"ip\"/></moduleconfig> " ascii fullword
$a8 = "\\Microsoft Office\\Office16\\outlook.exe" ascii fullword
$a9 = "\\Microsoft Office\\Office11\\outlook.exe" ascii fullword
$a10 = "\\Microsoft Office\\Office15\\outlook.exe" ascii fullword
$a11 = "\\Microsoft Office\\Office12\\outlook.exe" ascii fullword
$a12 = "\\Microsoft Office\\Office14\\outlook.exe" ascii fullword
$a13 = "TEST.TEMP:" ascii fullword
$a14 = "Chrome_WidgetWin" wide fullword
$a15 = "o --disable-gpu --disable-d3d11 --disable-accelerated-2d-canvas" ascii fullword
$a16 = "NetServerStart" ascii fullword
condition:
6 of ($a*)