Windows_Trojan_Trickbot_618b27d2
Description
Targets Outlook.dll module containing functionality used to retrieve Outlook data
Query · yara
strings:
$a1 = "OutlookX32.dll" ascii fullword
$a2 = "Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook" wide fullword
$a3 = "Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook" wide fullword
$a4 = "Software\\Microsoft\\Office\\15.0\\Outlook\\Profiles\\Outlook" wide fullword
$a5 = "OutlookX32" ascii fullword
$a6 = " Port:" wide fullword
$a7 = " User:" wide fullword
$a8 = " Pass:" wide fullword
$a9 = "String$" ascii fullword
$a10 = "outlookDecrU" ascii fullword
$a11 = "Cannot Decrypt" ascii fullword
$a12 = " Mail:" wide fullword
$a13 = " Serv:" wide fullword
$a14 = ",outlookDecr" ascii fullword
$a15 = "CryptApi" ascii fullword
condition:
5 of ($a*)