Windows_Trojan_Trickbot_46dc12dd
Description
Targets newBCtestDll64 module containing reverse shell functionality
Query · yara
strings:
$a1 = "setconf" ascii fullword
$a2 = "<moduleconfig><autostart>yes</autostart><sys>yes</sys><needinfo name = \"id\"/><needinfo name = \"ip\"/><autoconf><conf ctl = \""
$a3 = "nf\" file = \"bcconfig\" period = \"90\"/></autoconf></moduleconfig>" ascii fullword
$a4 = "<moduleconfig><autostart>yes</autostart><sys>yes</sys><needinfo name = \"id\"/><needinfo name = \"ip\"/><autoconf><conf ctl = \""
$a5 = "<addr>" ascii fullword
$a6 = "</addr>" ascii fullword
condition:
4 of ($a*)